How the scam operates.
myetherawllet.com とその変種である myetherwlalet.com のサイトは、イーサリアムウォレットのインターフェースを装っており、広く知られた正規のウォレットサービスとほぼ同一の外観を利用しています。想定される標的は、URLを打ち間違えて到達した、あるいは他所で配布されたフィッシングリンクを経由して訪れた、当該サービスの既存利用者です。表向きの提供価値はイーサリアム資産へのアクセスですが、その実態は欺瞞にあります。
この詐欺の手口は、タイポスクワットを基盤とした認証情報窃取(クレデンシャルハーベスティング)の典型と一致します。訪問者は通常、資産にアクセスするためと称して、ウォレットの重要な認証情報、秘密鍵、またはシードフレーズの入力を求められます。正規の非カストディアル型イーサリアムウォレットアプリケーションでは、こうした入力はすべてクライアント側で処理されますが、この種の模倣された複製サイトでは、同じ入力が運営者の管理するインフラへ送信されます。その結果として、ウォレットが保有するあらゆる資産の支配権が、利用者に気づかれることなく、かつ取り消し不能な形で移転してしまいます。
被害は通常、利用者が取引を試みた際に残高がすでに移動済みであることに気づいたとき、あるいは本物のサービスに戻った際に口座が空になっていることを発見したときに表面化します。その時点で、当該サイトはすでに目的を果たしています。運営者が新たなドメインの変種を用いて詐欺を繰り返すことに対する実質的な障害は存在せず、オンチェーン取引の不可逆性が回復の選択肢を大きく制限しています。
Red flags we documented.
- 01Typosquat Domain ConstructionThe two registered domains, myetherawllet.com and myetherwlalet.com, are character-level transpositions of a widely recognised Ethereum wallet name. Registering deliberate misspellings of trusted service names is a documented technique for intercepting users who arrive by mistyping a URL they intended to visit.
- 02Multiple Lookalike Domain VariantsThe operation registered at least two distinct misspelling variants under what appears to be a coordinated campaign. The presence of several lookalike domains signals organised fraud infrastructure rather than an opportunistic one-off registration.
- 03Active Presence on Community BlacklistsBoth domains appear in the CryptoScamDB blacklist, a community-maintained registry with documented coverage of active phishing and theft operations across the cryptocurrency ecosystem. Blacklist inclusion at two separate entries suggests the domains were independently flagged or reported.
- 04Private Key and Seed Phrase Solicitation RiskAny interface that solicits a private key or seed phrase presents a total-loss risk when the site cannot be verified as the genuine service. Legitimate non-custodial wallet interfaces do not transmit these values off-device; a replica that does so drains the wallet silently and without warning.
- 05Absence of Verifiable Operating HistoryThe domains carry no verifiable indicators of a legitimate service: no documented development team, no open-source repository, no auditable codebase, no regulatory disclosure. In the legitimate wallet space, established services are publicly accountable; the absence of these markers is a significant signal.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.