How the scam operates.
nnyetherwallet.comは、機能するイーサリアムウォレットのインターフェースを装っており、広く認知されているセルフカストディ(自己管理型)ウォレットサービスであるMyEtherWalletを模倣するように構築されている。当該ドメインは、正規サービスとの違いが接頭辞の文字の入れ替え一つに過ぎず、「my」を「nny」に置き換えたものである。これは意図的なタイポ(誤入力)の罠であり、正規アドレスを打ち間違えた利用者や、誤解を招くリンクをたどった利用者を捕捉し、初見では正規プラットフォームと見分けがつかないように設計されている。
この手口は、フィッシングのうち認証情報窃取(クレデンシャル・ハーベスティング)の類型に属する。訪問者は通常、既存のウォレットへのアクセスや復元を装って、秘密鍵、ニーモニック・シードフレーズ、またはキーストアファイルの入力を求めるウォレットインターフェースを提示される。これらの認証情報はローカルで処理されるのではなく、運営者によって取得される。秘密鍵およびシードフレーズは、関連するオンチェーン資産すべてに対する無条件かつ取り消し不能な支配権を付与するため、運営者はそれ以上のやり取りを要することなく、被害者の保有資産を直ちに引き抜くことができる。
破綻が明らかになるのは、情報を送信した後になってからである。ウォレットへのアクセスは復元されず、それどころか被害者は、自らが承認していない送金がすでにオンチェーンで完了していることに気づく場合がある。この段階では、資金は通常、運営者が支配する中継アドレスへと移動済みである。ブロックチェーン上の取引は不可逆であり、チャージバックの仕組みも、資産を凍結または回収できる管理権限も存在しない。回収が実現する場合でも、それは調査による追跡や、取引所ないし法執行機関との連携にかかっている。
Red flags we documented.
- 01Typosquat domain targeting a recognised wallet brandThe domain 'nnyetherwallet.com' deviates from MyEtherWallet's address by a single character substitution. This construction is not coincidental. It is engineered to intercept users who make minor typographical errors, placing a malicious interface in the path of traffic intended for a legitimate service.
- 02CryptoScamDB blacklist confirmationThe domain is listed in the CryptoScamDB blacklist, a community-maintained registry of verified fraudulent cryptocurrency sites. Inclusion reflects reported victim activity and analysis of the domain's operational purpose, and constitutes a recognised industry-level fraud signal.
- 03Solicitation of private credentials via web interfaceNo legitimate self-custody wallet service requires users to enter private keys, seed phrases, or keystore files into a browser-based form. Any platform that does so is operating a credential-harvesting interface. This is the defining behavioural signal for this class of fraudulent operation.
- 04Anonymous operator with no regulatory footprintThere is no disclosed business entity, registered operator, or regulatory filing associated with this domain. Operational anonymity is a consistent feature of platforms designed to defraud without accountability, as it forecloses any civil or regulatory avenue for victim recourse.
- 05Immediate and irreversible asset exposure on credential entryOnce private credentials are submitted, the operator holds unconditional access to all associated on-chain assets. Transfers initiated by a malicious holder of these credentials cannot be reversed or intercepted. There is no escrow period, no dispute window, and no custodial protection of any kind.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.