How the scam operates.
このドメインは、ウェブ上で利用できるイーサリアム・ウォレットの管理インターフェースを装っています。運営者は信頼されているウォレットサービスの外観を再現し、フィッシングリンク、酷似した広告、あるいは正規ドメインよりも上位に不正ドメインを表示する検索結果を経由して到達する利用者を標的としています。表面的な体験は一見して本物のサービスと見分けがつかないように設計されており、欺瞞はドメイン名そのものに組み込まれています。
その手口は同形異義語攻撃です。Punycodeエンコードにより、ドメイン内の一つ以上の文字を非ASCII文字集合から取りつつ、大半のブラウザでは見慣れたASCII文字として表示させることが可能になります。URLは既知のウォレットサービスと同一に見えますが、実際には運営者の管理下にあるホストへ解決されます。入力されたシードフレーズ、秘密鍵、または認証情報はすべて運営者へ送信されます。ウォレットのインターフェースは、発覚を遅らせるために一時的に正常に動作することがあります。
被害者が資金にアクセスしようとした際に、残高が抜き取られているか、サイトが消失していることに気づき、破綻が表面化します。その時点では、入力されたシードフレーズはすでに関連するウォレットの一掃に使われています。これらの活動にはサポート機能も運営者の身元も一切ありません。ドメインは使い捨ての道具であり、その有用性が尽きると、通常は痕跡を残さず放棄されます。
Red flags we documented.
- 01Punycode homograph construction in the domain nameThe xn-- prefix signals a punycode-encoded internationalised domain. A visually identical non-ASCII character substitutes for a standard letter, producing a URL that passes casual inspection but resolves to a host unrelated to the service it mimics. This is a deliberate evasion technique, not a registration accident.
- 02CryptoScamDB blacklist inclusionThe domain is indexed on CryptoScamDB's community-maintained blacklist of confirmed phishing and fraud infrastructure. Inclusion reflects a verified report from the security community, not an automated keyword filter.
- 03Wallet interface clone targeting seed phrase entryPlatforms that replicate wallet interfaces serve one primary purpose: capturing seed phrases or private keys. Any site requesting these inputs that cannot be verified as the canonical service should be treated as hostile. No legitimate wallet service requires a seed phrase entered via a web form.
- 04No verifiable operator or registration signalOperations built on homograph domains carry no regulatory filing, no published company details, and no accountable team. The structural anonymity is intentional; it ensures there is no entity to pursue if funds are lost.
- 05Arrival-path risk: links over direct navigationHomograph phishing relies on victims arriving via a link rather than typing an address. Users who click wallet links from emails, social media, or advertisements are exposed in ways that those who bookmark and type the canonical address directly are not.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.