How the scam operates.
この手口は、著名なイーサリアムのウォレットサービス向けの正規のソフトウェア更新ポータルを装っています。ドメインの構成は、典型的ななりすましのパターンに沿っており、運営者は確立されたブランド名の前に「update」という語を付加することで、公式のメンテナンスやアップグレードの通知であるかのように読めるサイトを作り上げています。想定されている対象は、正規サービスの既存利用者であり、メール、ソーシャルメディア、あるいは不正な検索連動型広告を通じてフィッシングリンクを受け取り、ウォレットが期限切れになる、または機能を失う前に「更新」するよう誘導された人々です。
その仕組みは、全面的にソーシャルエンジニアリングに依存しています。訪問者には、正規サービスの視覚的デザインを精巧に模倣したインターフェースが表示されます。次に運営者は、更新手続きを完了するには確認が必要であるという口実のもと、シードフレーズ、秘密鍵、あるいはウォレットの認証情報を入力するよう利用者に促します。これが中核的な欺瞞です。正規のウォレットサービスが、利用者に秘密鍵やリカバリーフレーズをウェブポータル経由で入力させることは決してありません。これらの認証情報がいったん送信されると、運営者は関連するすべてのウォレットへの完全かつ取り消し不能なアクセス権を得ます。
被害が生じる時点は即時であり、通常は全損に至ります。ブロックチェーンの取引は最終的なものであるため、運営者は認証情報を取得してから数秒以内に、被害者が対応する余地を得る前に、アクセス可能なすべての資金を引き出すことができます。利用者が異変に気づくのは、説明のつかない残高ゼロを目にした後であるのが通例です。その時点では、ドメインはすでにオフラインになっているか、新たな URL へ切り替わっていることが多く、運営者は追跡可能な身元、登録された事業体、顧客サポート窓口を一切残していません。
Red flags we documented.
- 01Typosquat domain targeting an established wallet brandThe domain prepends "update" to a recognised wallet service name, a construction designed to pass casual visual inspection. This is a documented phishing technique with no legitimate use case. Genuine wallet providers do not operate update portals on separate domains.
- 02"Update" framing as a credential-harvesting triggerPrompting users to submit seed phrases or private keys through any web form is categorically illegitimate. The update narrative exists solely to manufacture urgency and a plausible-sounding reason to surrender credentials that should never leave a local device.
- 03CryptoScamDB blacklist listingThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of addresses associated with confirmed fraudulent activity. Inclusion indicates the operation had already been flagged and reported at the time of listing.
- 04No verifiable operator identity or registered entityLegitimate financial or wallet services maintain publicly verifiable corporate registrations, regulatory disclosures, and support infrastructure. This operation provides none of those. The absence of any traceable organisational identity is consistent with a disposable phishing asset.
- 05Single-use infrastructure patternOperations of this type are designed to be ephemeral. The domain is acquired cheaply, deployed quickly, and abandoned once flagged or once enough credentials have been harvested. This pattern makes asset recovery and legal pursuit exceptionally difficult.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.