How the scam operates.
当該サイトは、暗号資産分野で最も広く認知されている非カストディアル型ウォレットのインターフェースの一つから名称をそのまま借用し、正規のイーサリアムウォレットサービスを装っています。ブランド上の表示は、本物の製品に慣れた利用者を安心させるよう設計されており、見覚えのある用語によって警戒心を緩めさせることを狙っています。標的とされるのは、セルフカストディ型ウォレットを管理するイーサリアム保有者であり、検索結果やソーシャルメディアのリンク、または当該ドメインへ誘導するフィッシングメッセージを経由して到達する可能性があります。
この種の手口は通常、模造したインターフェースを表示し、アカウントへのアクセスや復旧を装って利用者の秘密鍵やシードフレーズの入力を求める形で機能します。ひとたび入力されると、運営者は当該ウォレットを取り消し不能な形で支配下に置きます。イーサリアムの取引は不可逆であり、第三者の承認を必要としないため、資金は即座に、かつ救済の余地なく抜き取られてしまいます。この偽装は、標的とするブランド名を一字一句そのまま再現したうえで、捏造したトップレベルドメインの接尾辞を付加したドメイン名そのものによって、さらに強化されています。
問題が表面化するのは、利用者が正規のサービスを通じて自身のウォレットにアクセスしようとし、資産がもはや存在しないことに気づいた時点です。その段階では、フィッシングサイトは通常すでに応答を停止しており、運営者の連絡先情報も入手できません。ネットワークの観点からは認証情報が自発的に入力されたものであるため、ブロックチェーン上の取引には取り消しの仕組みがありません。被害者の手元には送金の記録がオンチェーン上の証拠として残るものの、専門的な調査なしには受取アドレスを追及する現実的な手段がありません。
Red flags we documented.
- 01Non-standard domain suffix signals an illegitimate operationThe '.active' top-level domain is not recognised by the Internet Assigned Numbers Authority, which maintains the authoritative registry of valid TLDs. A legitimate wallet service would not operate on a non-standard or fabricated domain extension. This alone is sufficient grounds for immediate suspicion.
- 02Name mimics a recognised Ethereum wallet platformThe domain reproduces the exact name of an established Ethereum wallet interface, differing only in the top-level domain. This pattern, known as brand impersonation or typosquatting, is consistently associated with credential-harvesting operations that rely on users recognising the name without inspecting the full domain.
- 03Listed on the CryptoScamDB blacklistThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed fraudulent cryptocurrency addresses and domains. Inclusion indicates the site has been reported and verified as malicious by independent reviewers, placing it in confirmed rather than suspected territory.
- 04Credential-entry interface carries irreversible riskAny interface requesting a private key or seed phrase outside of a hardware wallet signing flow should be treated as a hostile surface. There is no legitimate operational reason for a web-based wallet interface to require this information. Entry of these credentials constitutes immediate and total loss of wallet control.
- 05No traceable operator or regulatory registrationNothing in the available record indicates this operation is registered with any financial authority, has a disclosed legal entity, or provides verifiable contact information. The absence of operator transparency is consistent with a disposable phishing asset rather than a legitimate service.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.