How the scam operates.
ドメインxn--myetherwllet-59a.comは、国際化ドメイン名(IDN)システムを通じて登録されています。これは、非ASCIIのUnicode文字をpunycode記法によってウェブアドレスへエンコードすることを可能にする仕組みです。表示されるURLは、広く利用されている自己管理型Ethereumウォレットサービスのアドレスと視覚的に区別がつかない、あるいはほとんど区別できないものとなっています。運営者は、フィッシングリンク、汚染された検索結果、またはブラウザへの入力誤りを経由して到達するEtherおよびERC-20トークンの保有者を標的としています。
このプラットフォームの運用上の機能は、認証情報の窃取にあります。訪問者は正規のウォレットサービスを模したインターフェースに遭遇し、アカウントへのアクセスや復旧を装った口実のもとで秘密鍵やシードフレーズの入力を求められます。入力された認証情報はすべて運営者によって傍受されます。Ethereumネットワークには中央の管理者が存在しないため、秘密鍵を保有することはそれに関連するすべての資金に対する即時の支配権を意味し、被害者が侵害に気づく前に運営者がウォレットを空にすることを可能にします。
侵害は通常、被害者が正規のアカウントだと思い込んでいるものへアクセスしようとして残高が空になっていることに気づいたとき、あるいはブロックチェーン上で不正な取引を確認したときに初めて明らかになります。その時点では、サイトはすでにその目的を果たし終えています。連絡すべき発行体は存在せず、チャージバックの仕組みもなく、オンチェーン送金に対する異議申立ての期間もありません。残されるのは、送金先ウォレットアドレスの法的証拠記録であり、場合によっては当該ドメインをより広範なフィッシングネットワークへ結びつけるインフラのパターンです。
Red flags we documented.
- 01Punycode homograph registrationThe xn-- prefix marks this as an internationalised domain constructed to appear identical to a legitimate service's address in standard browser rendering. No genuine service registers its own brand name this way. The technique exists specifically to exploit the visual trust users place in familiar-looking URLs.
- 02CryptoScamDB blacklist inclusionThe domain appears in the CryptoScamDB community blacklist, a curated register of addresses associated with phishing, wallet draining, and digital asset theft. Inclusion reflects reported evidence reviewed by the community, not automated keyword matching alone.
- 03Credential-harvesting interface patternAny platform soliciting private keys or seed phrases through a wallet import or recovery form is operating outside the accepted norms of legitimate self-custody tooling. Genuine wallet software processes these values locally and never transmits them to a remote server.
- 04No verifiable operator or legal presenceOperations of this pattern carry no identifiable company registration, no named founding team, and no regulatory disclosure. The absence of these signals is consistent with a disposable phishing infrastructure rather than a legitimate financial service.
- 05Asset class selected for irreversibilitySelf-custodied Ether and ERC-20 tokens are targeted precisely because on-chain transfers are final. No central authority can reverse a confirmed transaction, structurally foreclosing the most common recovery routes available to victims of financial crime.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.