How the scam operates.
この行為は、広く認知されたセルフカストディ型ウォレットサービスのブランドをほぼ完全に再現し、トップレベルドメインのみが異なるドメイン名を採用することで、正規のEthereumウォレットインターフェースを装っています。当該サイトは、正規サービスへの自然な遷移を通じてではなく、ソーシャルメディア、メールキャンペーン、検索エンジン広告といったフィッシング経路で不正なリンクに遭遇した利用者を捕捉するよう設計されているとみられます。
この種のウォレット偽装プラットフォームは、訪問者から直接、秘密の認証情報を要求します。一般的にはシードフレーズ、秘密鍵、または暗号化されたキーストアファイルであり、ウォレットのインポート、アカウントの復元、取引の承認といった口実のもとで提示を求められます。利用者がウェブインターフェースを通じてこれらの認証情報を送信すると、運営者はその認証情報が管理するあらゆるウォレットへの完全なアクセス権を取得します。資金は通常、認証情報の取得から数分以内に出金を実行する自動化されたプロセスを用いて、侵害されたウォレットから速やかに移動されます。
決定的な破綻点は、回復不能であるという点にあります。Ethereumネットワーク上の取引は、いったんオンチェーンで確定されると取り消しや撤回ができないため、侵害されたウォレットから流出した資産は、技術的手段による回復が永久に不可能となります。被害者が損失に気づくのは通常、自身の正規ウォレットにアクセスしようとした時点であり、その時にはすでに残高は空にされており、不正なプラットフォームには異議申し立てや救済の手段が一切残されていません。
Red flags we documented.
- 01Exact brand impersonation via TLD substitutionThe domain reproduces the full name of a well-known Ethereum wallet platform, substituting only the top-level domain. This is a deliberate impersonation pattern intended to exploit user familiarity and typographical error. Visitors navigating to this address may reasonably believe they have reached the legitimate service.
- 02Non-standard TLD outside recognised registrar oversightThe ".aigo" extension does not correspond to any ICANN-recognised top-level domain. Legitimate financial services platforms do not operate from unrecognised TLDs. This choice of domain signals disposable infrastructure designed to evade conventional takedown processes.
- 03Presence on CryptoScamDB community blacklistThe domain is listed on CryptoScamDB's community-maintained blacklist, a database of addresses and URLs associated with documented cryptocurrency fraud. Inclusion reflects reported harmful activity and community verification of the warning.
- 04Credential-harvesting attack surfaceWallet impersonation operations solicit private keys and seed phrases through web forms. No legitimate wallet service requests these credentials via a browser interface. Any platform that does so should be treated as a credential-harvesting operation; submission results in total and irreversible loss of associated assets.
- 05No verifiable operator or regulatory identityThere is no documented company registration, regulatory licence, or verifiable operator identity associated with this domain, consistent with the anonymous, disposable infrastructure typically used in phishing campaigns targeting cryptocurrency holders.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.