How the scam operates.
この手口は、正規のイーサリアムウォレットのインターフェースを装い、広く利用されている暗号資産ウォレットサービスとの見た目の類似性を悪用するものです。確認されている2つのドメイン、myetherwallte.com および myetherwalelt.com は、正規サービスと文字の入れ替えや挿入のみが異なっており、馴染みのあるアドレスを打ち間違えた利用者を捕捉するように設計されています。その狙いは、信頼されているセルフカストディ型ウォレットのインターフェースを忠実に複製し、注意を払わない訪問者がすり替えに気づかないようにすることにあると見られます。
その基盤となる仕組みは、暗号資産の保有者を標的とする、十分に文書化されたフィッシングの手口に沿ったものです。打ち間違えたURLや操作された検索結果を経由してサイトに到達した訪問者は、秘密鍵、シードフレーズ、またはログイン認証情報の入力を求めるウォレットのインターフェースに誘導されます。これらの情報がいったん送信されると、運営者は関連するあらゆるウォレットへの完全かつ不可逆的なアクセスを得ます。ブロックチェーン上の取引は取り消すことができないため、侵害されたウォレットから資産が移動された場合、従来の手段で資産を回復する現実的な道は残されません。
問題が表面化するのは、被害者が正規のウォレットにアクセスしようとした際に、認証情報がもはや機能しない、あるいは資金が許可なく既に移動されていることに気づいた時点です。この手口に沿った犯行は通常、認証情報を取得してから数分以内に行われ、被害者が事態を認識する前にウォレットを空にします。その後の連絡の試みは何の成果も得られません。インフラは通常、検知されたり十分な数の被害者が通過したりすると、放棄されるか入れ替えられます。
Red flags we documented.
- 01Typosquat Domain ArchitectureBoth confirmed domains are deliberate transpositions of a widely-recognised Ethereum wallet service name. The misspellings require no social engineering beyond exploiting routine typing errors, allowing the operation to harvest victims passively from organic navigation mistakes.
- 02Multiple Alias Domains RegisteredThe operation maintains at least two confirmed alias domains, indicating coordinated infrastructure rather than an isolated incident. Multiple domains extend reach and provide redundancy if one address is taken down or blacklisted by browser security tools.
- 03CryptoScamDB Blacklist InclusionBoth domains appear in the CryptoScamDB community blacklist, referenced by wallet providers and browser extensions to block access to known phishing infrastructure. Inclusion across two separate entries reflects confirmed, community-verified evidence of fraudulent activity.
- 04Credential-Harvesting Platform PatternSites impersonating cryptocurrency wallet interfaces serve a single operational purpose: collecting private keys or seed phrases. No legitimate wallet service solicits these credentials through a web form. Any interface doing so should be treated as hostile regardless of its visual presentation.
- 05No Verifiable Operator or Regulatory StandingThe operation presents no identifiable registered entity, public operator, or regulatory licence. Legitimate wallet services maintain public accountability structures. The absence of any such structure is consistent with the disposable infrastructure typical of short-cycle phishing campaigns.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.