How the scam operates.
当該サイトは、正規のEthereumウォレットのインターフェースを装い、確立された著名なウォレットサービスの名称とそれが想起させる信頼性を借用しています。その運用面、ドメイン名、想定される視覚的デザイン、利用者に提示される文言は、一見しただけでは本物のプラットフォームと見分けがつかないように構築されています。標的となるのは、ウォレットへのアクセスを求めるEthereum利用者であり、特に入力済みのブックマークからではなく、検索エンジン、ソーシャルメディアのリンク、または転送されたURLを経由して到達する層です。
その手口は、ウォレットを狙うフィッシング行為に共通する標準的な認証情報窃取モデルに沿ったものです。訪問者は、アカウントへのログインまたはアクセス復旧を装って、シードフレーズ、秘密鍵、またはキーストアファイルの入力を促されます。運用者は、入力された瞬間にこれらの認証情報をサーバー側で取得します。Ethereumの秘密鍵は関連する資金に対する無条件かつ取り消し不能な支配権を付与するため、一度の取得が成功するだけで対象ウォレットに保有される全資産を空にするには十分であり、被害者によるそれ以上の操作は不要です。
異変が明らかになるのは、通常、認証情報がすでに送信された後です。利用者は、インターフェースがエラーを返すか、予期しない形でリダイレクトされるか、あるいは見かけ上は正常に動作している一方で並行する処理が密かにウォレットを空にしていることに気づきます。その不一致が調査される頃には、運用者は一つまたは複数の中継アドレスを経由して資金を移動させており、専門的なツールなしではオンチェーンでの追跡が困難になっています。プラットフォーム内に復旧や異議申立ての仕組みは存在せず、そもそも用意される意図もありませんでした。
Red flags we documented.
- 01TLD substitution as impersonation techniqueThe domain replicates the name of a recognised Ethereum wallet service while substituting a different top-level domain. This pattern, known as TLD spoofing, is a deliberate attempt to exploit typographical error and user inattention. Legitimate wallet providers do not operate across multiple conflicting TLDs.
- 02.su TLD registration patternThe .su ccTLD (administered for the former Soviet Union) remains operational and is disproportionately represented in fraud and phishing infrastructure due to minimal registration oversight and enforcement cooperation. Its use here provides no legitimate geographic or operational justification.
- 03CryptoScamDB blacklist confirmationThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained dataset used by wallet software, browser extensions, and security researchers to block known malicious addresses. Inclusion reflects documented community reports, not automated heuristics alone.
- 04Private-key harvest, irreversible loss exposureWallet phishing operations targeting seed phrases or private keys expose victims to total, permanent asset loss. Unlike payment card fraud, there is no chargeback mechanism and no custodial institution to contest with. Any platform requesting a private key or seed phrase outside of a locally-running, verifiable application should be treated as hostile.
- 05Absence of verifiable operational historyOperations of this type typically lack any auditable history, no company registration, no named team, no published security disclosures, and no track record predating the fraud campaign. The use of an impersonation domain further forecloses any legitimate identity claim the operator might otherwise make.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.