How the scam operates.
CryptoScamDB が管理する公開記録は、xn--myeterwallet-jl6c.com を詐欺監視対象の登録項目として特定しています。運営は xn--myeterwallet-jl6c.com を通じて行われています。
CryptoScamDB 自身の警告には次のように記されています。「Homoglyph。サブカテゴリ:MyEtherWallet。報告者:CryptoScamDB」
この種のウォレット資産流出(ドレイン)は、悪意のある承認(approval)トランザクションへ利用者に署名させることに依存しており、その手口は偽装されたミントページ、偽のエアドロップ受領、正規の dApp へのなりすましを介して行われることが多くあります。利用者は通常、ウォレットの資産が流出するまで承認が付与されたことに気づかず、最初の署名から数時間後あるいは数日後になって流出が発生する場合もあります。
Red flags we documented.
- 01Punycode Encoding Used to Obscure Domain IdentityThe xn-- prefix is the technical marker of a Punycode-encoded internationalised address. This encoding is a documented vector for IDN homograph attacks, in which the rendered URL is made to appear identical to a trusted domain while the underlying address points to an entirely different server controlled by a third party.
- 02Confirmed Inclusion on CryptoScamDB BlacklistThe domain appears on the CryptoScamDB community blacklist, a researcher-maintained registry of addresses independently flagged as associated with cryptocurrency fraud. Inclusion reflects a determination by external investigators that the domain poses active harm to users.
- 03Impersonation of a Recognisable Wallet PlatformThe decoded domain resolves to a close visual approximation of myetherwallet.com, a service with a large and established user base. Operators target this brand precisely because its users are likely to hold meaningful balances and may not scrutinise the address bar carefully before entering sensitive credentials.
- 04Seed Phrase Capture as the Core MechanismNon-custodial wallet interfaces require users to enter seed phrases or private keys to restore or import accounts. A cloned interface that intercepts these inputs requires no further access: possession of a seed phrase confers complete and permanent control over every asset in the associated wallet, across all networks.
- 05Disposable Infrastructure Signals Deliberate FraudHomograph impersonation domains are typically registered at low cost, used during a concentrated phishing campaign, and abandoned once blacklisting reduces traffic. The narrow window between deployment and discovery is itself a characteristic of fraudulent operations rather than legitimate services.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.