How the scam operates.
myetherwallet.info は、機能的な Ethereum ウォレットのインターフェースを装い、ウォレットへのアクセスを探しているユーザーや、見慣れたアドレスをブラウザに入力する際に打ち間違えたユーザーを標的としています。同ドメインは、広く知られた暗号資産ウォレット提供事業者のドメインに酷似しており、その .info という接尾辞と、確立された .com 版との視覚的な類似性を利用して、正規であるかのような印象を作り出しています。想定されている対象は、なりすましの対象とされているブランドをすでに信頼しており、ドメインの拡張子を精査する可能性が低い Ethereum 保有者です。
この種の手口は通常、正規サービスの視覚的なデザインを高い精度で再現し、保有資産にアクセスするためと称して、秘密鍵、シードフレーズ、キーストアファイルといったウォレットの認証情報を入力するよう訪問者に促します。インターフェースが本物の製品に似ているため、ユーザーはしばしば疑うことなく、最も機密性の高い暗号情報を提供してしまいます。運営者はこのデータをサーバー側で取得し、それを用いて関連するウォレットから資金を抜き取りますが、その多くは送信から数分以内に行われます。
破綻が表面化するのは、被害者が取引を完了させようとしたり残高を確認しようとしたりした際にインターフェースが反応しないことに気づいたとき、あるいは自分の本物のウォレットが見覚えのない外部アドレスによって空にされていることを発見したときです。その段階に至るまでに、運営者はすでに認証情報を窃取し終えています。侵害された自己管理型ウォレットから移転された資産の回収は技術的に困難です。なぜなら、その移転は被害者自身の秘密鍵によって認証されており、したがってオンチェーン上では自発的な送金と見分けがつかないためです。
Red flags we documented.
- 01Domain Mimics a Recognised Wallet BrandThe .info domain closely replicates a well-established .com wallet address, a pattern consistent with typosquatting designed to intercept users who mistype or follow a malicious link. No affiliation with the original service exists, and the choice of extension appears deliberate.
- 02Listed on CryptoScamDB Community BlacklistThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed malicious cryptocurrency sites. Inclusion reflects prior community-verified harm and is treated by security tooling as grounds for automatic blocking.
- 03Credential Entry Pattern Signals Harvesting OperationWallet impersonation platforms of this type solicit private keys, seed phrases, or keystore files. Legitimate non-custodial wallet interfaces do not require these credentials to be entered on a website under any circumstances. Any platform that does should be treated as hostile.
- 04No Verifiable Operator or Regulatory StandingThe domain carries no documented organisational identity, regulatory authorisation, or verifiable legal presence. Legitimate custodial or financial services are required to disclose these details in most jurisdictions; their absence is a material signal of illegitimacy.
- 05Asset Exposure is Immediate and IrreversibleOnce credentials are submitted to a harvesting operation, the operator can drain associated wallets within minutes. Blockchain transactions are irreversible and carry no chargeback mechanism. The window for any meaningful intervention is extremely narrow.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.