How the scam operates.
この手口は、正規のEthereumウォレットのインターフェースを装っています。当該ドメインは国際化ドメイン名(IDN)エンコーディングを用いて構築されており、これは一部のブラウザにおいて、基となるpunycode文字列ではなく、著名なウォレットプラットフォームと視覚的に区別がつかないUnicodeアドレスを表示させる技術です。標的となるのは、コピーされたリンク、検索結果、またはリダイレクトを通じて、当該サイトを本物のサービスだと信じてアクセスする、あらゆる暗号資産利用者です。
被害者は通常、電子メール、ソーシャルメディアの投稿、または有料検索広告に含まれるphishingリンクを経由して当該サイトに到達します。インターフェースは信頼されているウォレット製品を精巧に模倣しており、利用者は不審な点に気づくことなく、秘密鍵、シードフレーズ、またはアカウント認証情報を入力してしまいます。これらの入力情報は正当に処理されることなく、運営者によって窃取されます。この仕組みは、レンダリングエンジンが特定のUnicodeコードポイントを標準的なラテン文字として表示し、人間の目にはドメインが正しく見えるという点に依存しています。
欺瞞が明らかになるのは通常、被害者が自身のウォレットへアクセスを試みた際に資金が消失していること、または認証情報の入力後にインターフェースが応答しなくなっていることに気づいた時点に限られます。その時点で運営者は秘密鍵の情報を握っており、オンチェーン上の損失は回復不可能です。取引を取り消す発行体は存在せず、チャージバックの仕組みもなく、資産を信託として保管する保管機関もありません。その後、運営者を特定したり救済を求めたりする試みは誰にも届きません。当該インフラは当初から検証可能な身元を一切持たないよう設計されているためです。
Red flags we documented.
- 01Punycode homograph domain constructionThe domain uses internationalised domain name encoding so that it renders as a trusted platform name in browsers that display Unicode rather than punycode. Substituting visually identical Unicode characters for Latin letters in a domain has no legitimate commercial application; it is a documented credential-harvesting technique.
- 02CryptoScamDB blacklist presenceThe domain is listed on CryptoScamDB's community-maintained blacklist, a widely referenced aggregator of verified fraudulent cryptocurrency infrastructure. Inclusion reflects independent, third-party verification of fraudulent activity associated with this address.
- 03High-yield credential-harvesting target profileThe impersonated platform category is a self-custody Ethereum wallet interface, selected because users of such tools are conditioned to enter seed phrases and raw private keys. That input profile gives the operator immediate, irrevocable access to all associated funds without any further steps required.
- 04No identifiable operator or legal entityHomograph-attack infrastructure of this type consistently lacks any traceable registered business, named director, or accountable individual behind it. The absence of any legal identity is a structural feature of the operation, not an administrative oversight, and it is what makes recovery actions difficult to initiate.
- 05No regulatory authorisation or compliance recordThe operation carries no financial services authorisation from any recognised regulator, no published terms of service from an identifiable entity, and no verifiable compliance history. Legitimate wallet services operating in major jurisdictions are required to carry some form of registration or disclosure.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.