How the scam operates.
当該ドメインはInternationalised Domain Name(IDN、国際化ドメイン名)を悪用した攻撃を展開しており、Punycodeエンコーディングを用いることで、多くのブラウザ上では広く信頼されているイーサリアム用ウォレットのインターフェースとほぼ見分けがつかないウェブアドレスを表示します。運営者は本物そっくりのウォレットのフロントエンドを提示し、標準的なASCII文字の代わりに置き換えられたUnicode文字に利用者が気づかないことに付け込みます。サイトが利用者の既存のアカウント保有先に見える以上、勧誘や約束は一切必要ありません。
被害者の多くは、URLの打ち間違い、汚染された検索結果、あるいはSNS上で拡散されたフィッシングリンクを経由して到達します。表示されるドメインがほとんどのブラウザのアドレスバーで正しく見えるため、利用者は疑うことなくウォレットのシードフレーズ、秘密鍵、ログイン認証情報を入力してしまいます。運営者はこれらを即座に収集します。暗号資産の領域では、シードフレーズを保有することは、関連するすべての資金に対する完全かつ取り消し不能な支配権を握ることを意味します。そこにはサポート体制も、回復手段も、運営の背後にいる特定可能な当事者も存在しません。
破綻の瞬間は通常、静かに訪れます。認証情報を送信した後、利用者はリダイレクトされたり、一般的なエラー画面を表示されたり、空白のページに取り残されたりします。利用者が実際の保有残高を確認し、それが抜き取られていることに気づくまで、ウォレットには何の影響もないように見えます。オンチェーンの取引は取り消し不能であるため、従来の回復経路は閉ざされています。CryptoScamDBのブラックリストへの掲載は、当該ドメインがセキュリティ研究コミュニティによって稼働中のフィッシング基盤として特定されたことを裏付けています。
Red flags we documented.
- 01Punycode IDN Homograph ConstructionThe xn-- prefix identifies this as a Punycode-encoded Internationalised Domain Name, a class of address used in homograph attacks to substitute visually identical Unicode characters for standard ASCII letters. This construction has no legitimate purpose in a consumer-facing financial service and exists solely to deceive users who inspect the address bar.
- 02Wallet Credential Entry as the Target SurfaceDomains of this class are engineered to harvest seed phrases and private keys, the most irreplaceable credentials in cryptocurrency self-custody. Any interface soliciting these values outside of a verified, locally-installed wallet application should be treated as hostile, regardless of how familiar the address bar appears.
- 03CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a widely referenced registry of confirmed malicious cryptocurrency addresses maintained through open-source community verification. Inclusion reflects reported harm and peer review by security researchers, not automated flagging alone.
- 04No Identifiable Operator or Regulatory PresenceThe domain presents no verifiable corporate entity, regulatory registration, or contact information consistent with a legitimate financial services operator. Anonymous infrastructure of this kind is a baseline characteristic of phishing operations and makes civil or regulatory recourse effectively unavailable.
- 05Irreversibility Exploited as a Structural FeatureOperations of this pattern deliberately target blockchain-based assets because on-chain transfers cannot be reversed, disputed, or charged back. The absence of consumer protection is not incidental to the design. It is the reason this class of operation targets cryptocurrency wallets rather than conventional payment accounts.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.