How the scam operates.
この業者は、広く認知されているイーサリアムの自己管理型ウォレットサービスの名称と外見上の同一性を悪用している。ドメインは標的とするブランド名をほぼそのまま取り込んでおり、URLを打ち間違えた利用者、フィッシングメッセージ内のリンクをたどった利用者、または改ざんされた検索結果を通じてたどり着いた利用者を取り込む位置取りとなっている。トップレベルドメインの.airforceは、模倣元のブランドとの唯一の明白な相違点であり、時間に追われていたり軽度に注意散漫だったりする一般の利用者が見落としやすい細部である。
この種の業者は、標的のインターフェースの複製を表示し、秘密鍵、シードフレーズ、またはキーストアファイルを送信して認証するよう利用者に促す。これが中核的な仕組みである。すなわち、成功するためにインターフェースがウォレットとして機能する必要はない。利用者に一度だけ認証情報を入力させればよいのである。これらの認証情報は運営者に送信され、運営者はその後、対応するウォレットに独自に、かつ自らの選んだタイミングでアクセスできる。サイトは疑念を遅らせるため、ログイン成功を装う場合がある。
被害者は通常、一見すると通常のログインを行った後にウォレット残高が枯渇していることに気づき、詐欺を発見する。オンチェーンの送金は取り消し不能であるため、認証情報の送信から資金の引き出しまでの時間が、理論上唯一介入が可能な局面であることが多く、その時間は急速に閉じてしまう。苦情が申し立てられる頃には、運営者は通常、追加のアドレスを経由して資金を処理し終えており、フィッシングのインフラ自体もオフラインにされているか、新たなドメインに移行している場合がある。
Red flags we documented.
- 01Brand impersonation in the domain nameThe domain reproduces the name of a legitimate, well-established Ethereum wallet service with no meaningful alteration. This is a deliberate tactic: the closer a fraudulent domain sits to a trusted name, the less cognitive effort a victim needs to expend to accept it as genuine.
- 02Anomalous top-level domain for a financial interfaceLegitimate cryptocurrency wallet services operate under conventional TLDs. The use of .airforce for what purports to be a wallet interface has no plausible commercial rationale and is a recognised marker of opportunistic phishing infrastructure assembled quickly and cheaply.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained register of confirmed malicious cryptocurrency addresses and domains. Inclusion indicates the site has been independently identified as a threat by researchers outside CryptoLeek.
- 04Credential-request pattern inconsistent with legitimate wallet operationAny web-based interface that requests a private key or seed phrase to grant wallet access is operating outside the security model of self-custody. Legitimate wallet interfaces of the type being impersonated here do not require server-side submission of these credentials under any normal circumstances.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.