How the scam operates.
このドメインは、Punycode形式の国際化ドメイン名(IDN)の仕組みを利用し、大半のブラウザにおいて著名なEthereumウォレットサービスと視覚的にまったく同一に表示されるウェブアドレスを構築している。元となるドメインをデコードすると、アドレスバー上では肉眼で識別できない文字の置き換えが含まれている。運営者は当該サイトを信頼できるセルフカストディ型のウォレットプラットフォームであるかのように見せかけ、誤入力されたURL、検索結果、あるいは共有されたフィッシングリンクを経由して訪れる利用者を捕捉する位置に配置している。
その運用形態は認証情報の窃取である。訪問者は通常、ウォレットのログインまたは復元の手順を模したインターフェースを提示され、シードフレーズ、秘密鍵、またはキーストアファイルの入力を求められる。これら3つの入力情報は、暗号資産ウォレットを完全に支配する権限を付与する唯一の手段である。送信された時点で当該情報は運営者へと転送され、その後はそれ以上のやり取りを要することなく被害者の資金へアクセスできる状態となる。この攻撃はマルウェアを必要とせず、被害者の端末に痕跡を残さない。
被害の発覚は、意図的に遅延させられることが多い。一部の実装では、認証情報の窃取後に被害者を本物のサービスへリダイレクトし、通常のセッションであるかのような錯覚を維持する。利用者は、取引を実行しようとして残高が枯渇していることに気づくまで、異常に気づかない場合がある。その時点では、資金はすでに1つ以上の中間アドレスを経由して移動していることが多く、オンチェーン上の追跡の手がかりは急速に途絶える。送金を取り消す仕組みは存在せず、回収は早期の発見と送金先ウォレットの調査的な追跡にかかっている。
Red flags we documented.
- 01IDN Homograph Domain PatternThe xn-- Punycode prefix indicates this domain contains a Unicode character substitution designed to mimic a legitimate wallet address. This is a recognised attack technique against cryptocurrency users; no genuine wallet service registers its primary domain in this encoding.
- 02CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of phishing infrastructure. Inclusion follows community review and indicates the domain has been verified as fraudulent by independent researchers.
- 03Seed Phrase Solicitation SignalWallet impersonation platforms of this type invariably request recovery phrases or private keys. No legitimate self-custody wallet requires a user to submit a seed phrase through a web interface to access an existing wallet. Any platform making this request should be treated as hostile.
- 04No Verifiable Operator IdentityThere is no documented corporate registration, regulatory standing, or named operator behind this domain. Legitimate wallet services, whether custodial or non-custodial, maintain transparent organisational identity and are reachable through official channels.
- 05Irreversible Loss ExposureCredential theft of this kind results in on-chain fund transfers that cannot be reversed or disputed. Unlike bank fraud, there is no institutional recourse. Recovery depends entirely on early detection and, in some cases, investigative tracing of destination addresses.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.