How the scam operates.
当該ドメインは、著名なEthereumのウェブウォレットサービスと視覚的にほぼ同一の模倣として自らを提示しています。Punycodeラベル(xn--という接頭辞)は、表示されるURL内の1文字以上が標準的なASCIIの英字ではなく、ラテン文字以外のUnicode範囲から取られていることを示しており、これはホモグラフ攻撃として知られる手法です。これに「wallet」という語のlを意図的に1文字省いた綴り誤りが組み合わされることで、当該アドレスは、見慣れたウォレットのURLを期待する利用者の表面的な目視確認を通り抜けるように構成されています。
この種の手口は通常、フィッシングメール、悪意ある検索広告、または乗っ取られたソーシャルメディアの投稿を通じて拡散され、被害者を、正規サービスの視覚的デザインを模した複製インターフェースへと誘導します。ページに到達すると、利用者はアカウントに「ログイン」または「復元」するためと称して、シードフレーズ、秘密鍵、またはキーストアファイルの入力を求められます。これらの認証情報は、セルフカストディ型ウォレットを管理するために必要な唯一の認証手段であり、第三者のサイトでこれらを入力することは、ウォレットの実効的な支配権を運営者へ引き渡すことを意味します。
認証情報が送信された瞬間、自動化されたスクリプトが通常、利用者がブラウザのタブを閉じる前の数秒以内に、ウォレット内に存在する資金をことごとく抜き取ります。後にサイトへ戻ろうとした被害者は、運営者がドメインを検知・指摘されると同時にインフラを切り替えるため、サイトに接続できなくなっていることが少なくありません。この方法で移動された資産の回収は、技術的にも管轄権の面でも複雑であり、その結果はブロックチェーン・フォレンジックと、資金がどれだけ迅速に先へ転送されたかに左右されます。
Red flags we documented.
- 01Punycode encoding signals a homograph operationThe xn-- prefix in the domain name indicates Punycode encoding, meaning the address contains Unicode characters designed to look identical to Latin letters at normal reading speed. Legitimate wallet providers do not use Punycode in their primary domains. This pattern is a recognised marker of credential-phishing infrastructure.
- 02Deliberate misspelling of a recognised wallet brandThe domain 'myetherwalet' omits one letter from the name of a well-known Ethereum wallet service. Typosquat domains are a documented distribution vector for wallet-credential phishing, exploiting fast or autocomplete-assisted URL entry by users who do not verify addresses character by character.
- 03Presence on CryptoScamDB community blacklistThe domain appears in the CryptoScamDB blacklist, a publicly maintained registry of addresses associated with cryptocurrency fraud. Listing reflects community-sourced confirmation of malicious intent, not an unverified allegation.
- 04Seed phrase solicitation is categorically unsafeAny platform requesting a wallet seed phrase or private key to authenticate a user is structurally fraudulent. No legitimate self-custody wallet service requires these credentials to be transmitted to a web server; they are intended to remain exclusively within the user's own device.
- 05Infrastructure pattern typical of high-rotation phishingHomograph and typosquat domains targeting wallet services are typically deployed in short bursts, making them difficult to take down before significant harm occurs. The low barrier to registering near-identical replacement domains means a blocked address can be substituted quickly by the same operator.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.