How the scam operates.
当該サイトは、正規のセルフカストディ型Ethereumウォレットのインターフェースを装い、EtherおよびERC-20トークンの保有者を標的としている。そのドメインはPunycodeエンコード(xn--というプレフィックスがその目印となる)を用いており、ブラウザのアドレスバーに表示された際に、広く認知されたウォレットサービスと視覚的に区別がつかないURLを生成する非ASCIIのUnicode文字を埋め込んでいる。利用者は、信頼できる宛先にたどり着いたと信じ込んでアクセスする。
その手口の中核をなすのはIDNホモグラフ攻撃である。よく知られたサービス名のASCII文字に視覚的に酷似するUnicode文字が、エンコードのレベルでドメインに埋め込まれている。フィッシングリンク、改ざんされた検索結果、あるいは入力ミスに近いタイプミスを経由してたどり着いた被害者は、正規のウォレットツールを模したインターフェースに遭遇する。当該サイトは、ウォレットのロックを解除すると称してシードフレーズ、秘密鍵、またはキーストアファイルの入力を求める。これらの認証情報は送信と同時に運営者へと伝送され、関連するすべてのアドレスに対する完全な支配権が運営者の手に渡る。
この侵害は通常、何の兆候もなく進行する。当該サイトは短時間の読み込み状態を装った後、空白の画面になるか、エラーを返すことがあり、窃取が行われたことを明示する合図は一切表示されない。被害者が損失に気づくのは概して数時間後あるいは数日後で、資金が見覚えのないアドレスへと移動させられていることを発見したときである。その段階では、資産は追跡を妨げる目的で多層的な送金を経て移動させられているのが通例であり、オンチェーンでの介入が可能な時間的猶予はすでに失われている。
Red flags we documented.
- 01IDN Homograph Domain ConstructionThe xn-- prefix identifies this as an Internationalized Domain Name using Punycode to embed non-ASCII characters that produce a visual clone of a legitimate service URL. This technique has no genuine application in consumer financial services; its documented use in this context is credential phishing.
- 02CryptoScamDB Blacklist InclusionThe domain is recorded on the CryptoScamDB community blacklist, a reference used by wallet developers, browser security extensions, and anti-phishing infrastructure. Independent third-party identification of this kind reflects active recognition of the domain as harmful.
- 03Credential Solicitation Through a Web InterfaceLegitimate self-custody wallet tools do not accept seed phrases or private keys through a browser form connected to a remote server. Any platform requesting these credentials via a web interface is operating contrary to foundational cryptographic security practice.
- 04Complete Operator AnonymityNo company registration, named personnel, regulatory licence, or auditable operational record has been documented for this site. Structural anonymity of this kind is a deliberate feature of phishing infrastructure, not an administrative oversight.
- 05A Pattern That Defeats Standard Safety PrecautionsUnlike phishing that relies on social engineering alone, an IDN homograph operation defeats a specific precaution: verifying the URL bar. Victims who follow standard safety guidance and check the domain before entering credentials may still be deceived, as the threat operates at the character-encoding level rather than the content level.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.