How the scam operates.
本ドメインは、xn--という接頭辞が示すとおりPunycodeエンコードを用いて構築されている。これは、標準的なASCII文字を視覚的に区別のつかないUnicodeの同等文字に置き換える手法である。その結果、生成されるURLは、ほとんどのブラウザのアドレスバー上で、著名なEthereumのウェブウォレットのインターフェースとほぼ完璧な複製として表示される。標的とされるのは、セルフカストディ型のウォレットツールに直接アクセスする暗号資産の保有者であり、とりわけフィッシングリンク、誤認を誘う検索広告、あるいは肉眼では同形文字の置き換えが判別できない形で共有されたURLを経由して到達する利用者である。
その手口は、十分に文書化されたIDN同形異義語の典型的なパターンに従っている。訪問者には標準的なウォレットアクセス用インターフェースが提示され、ウォレットの復元または接続を口実として、シードフレーズ、リカバリーフレーズ、または生の秘密鍵の入力が求められる。これらの情報を送信すると、認証情報は直接運営者に伝達され、運営者はそれらの情報から導出されるすべてのウォレットアドレスへの無条件のアクセス権を握ることになる。本プラットフォームは正規の機能を一切果たしておらず、その唯一の目的は認証情報の窃取である。
この欺瞞は、認証情報が送信された後になって初めて表面化する。最初に観察される兆候は、通常、無許可の資金移動、またはウォレットへのアクセスが突然失われることである。なりすましが特定される頃には、資産はすでに追跡を困難にする多層的な取引を経て移動していることが通例である。カスタマーサポートの窓口は存在せず、紛争解決の仕組みもなく、連絡を取るべき制度上の取引相手も存在しない。運営者の匿名性は偶発的なものではなく、この種の不正行為にとって構造的に不可欠なものである。
Red flags we documented.
- 01Punycode-Encoded Domain ConstructionThe xn-- prefix identifies this as an internationalised domain name using non-ASCII characters. In a financial services context, this construction has no legitimate use case: it exists specifically to produce a URL that looks identical to a trusted brand while resolving to unrelated infrastructure. Deliberate technical effort is required to register and deploy such a domain.
- 02Credential-Harvesting Interface PatternWallet impersonation operations of this type are built around a single objective: obtaining seed phrases or private keys. Any interface that solicits a seed phrase or raw private key is, by definition, designed to extract it. Legitimate self-custody wallet software does not transmit these credentials to a remote server under any circumstances.
- 03CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed phishing and fraud infrastructure in the cryptocurrency ecosystem. Inclusion reflects evidence review by contributors familiar with wallet impersonation patterns, not automated heuristic flagging alone.
- 04Absence of Verifiable Operator IdentityOperations of this type carry no verifiable legal identity, no registered business address, no named principals, and no regulatory authorisation in any jurisdiction. This absence is not an administrative oversight; anonymity is operationally necessary for a platform whose function is credential theft.
- 05Single-Purpose Infrastructure SignalA homograph domain targeting a wallet brand serves no plausible legitimate purpose. The Punycode construction, the wallet interface design, and the target user base combine into an unambiguous fraud pattern. There is no benign interpretation for this class of domain registration.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.