How the scam operates.
ドメインxn--mythrwallet-pkjc.comは国際化ドメイン名(IDN)であり、大半のブラウザのアドレスバーに表示された際、広く利用されているセルフカストディ型のEthereumウォレットサービスと視覚的に区別できない文字列として表示されます。運営者はそのウォレットインターフェースを忠実に複製したものを提示し、自身で秘密鍵を管理する暗号資産保有者を標的としています。
この手口は、Unicodeの文字エンコードを悪用し、識別可能なウォレットドメイン内のASCII文字を、他の文字体系に由来する視覚的に同一の文字に置き換えるものであり、IDNホモグラフ攻撃と呼ばれます。フィッシングリンクをたどった訪問者は、正規のサービスを複製したページに到達します。当該サイトは、これを通常のログインまたは復元の手順であるかのように装い、シードフレーズ、秘密鍵、またはキーストアファイルの入力を促します。入力された認証情報はサーバー側で取得され、関連するウォレットアドレスから資産を抜き取るために利用されます。
被害者が侵害に気づくのは、通常、資産が自身のウォレットから流出した後です。秘密鍵の窃取は大半のパブリックブロックチェーン上で取り消し不能であるため、回収の仕組みは存在しません。一部のブラウザはアドレスバーに生のPunycode形式を表示し、これが警告として機能する場合もありますが、この保護機能の適用は一貫しておらず、フィッシングリンクの配布に通常伴うソーシャルエンジニアリングの圧力の下では、ほとんど気づかれることがありません。
Red flags we documented.
- 01IDN homograph domain registered to mimic a legitimate walletThe xn-- prefix in the domain's technical form is the Punycode encoding marker for internationalised domain names. Its presence in this context indicates that one or more visible characters are Unicode lookalikes rather than standard ASCII. This technique is used almost exclusively for deception rather than for legitimate multilingual purposes in the cryptocurrency sector.
- 02Credential request is the mechanism of theftAny wallet interface that requests a seed phrase, private key, or keystore file as part of a login or recovery flow is exhibiting a primary phishing signal. Legitimate self-custody wallet software does not transmit these credentials to a remote server. The act of entering them into this site is the point of compromise, not a precondition for access.
- 03Blacklisted by CryptoScamDBThe domain appears on the CryptoScamDB community blacklist, a curated registry of cryptocurrency phishing and fraud infrastructure. Inclusion follows verified reports of deceptive behaviour or confirmed credential-harvesting activity, representing independent corroboration of the threat classification.
- 04No traceable operator or accountable entityPhishing domains of this pattern are registered anonymously, typically via privacy-shielded registrars, and carry no verifiable operator identity, terms of service, or regulatory registration. The absence of any accountable entity is consistent with infrastructure designed for rapid deployment and abandonment after detection.
- 05Variant domains likely active beyond this single addressIDN spoofing campaigns commonly rotate across character-variant domains as individual addresses are detected and blacklisted. The site may already be inactive, but the underlying operation may have migrated. Any credentials entered at this address prior to its blacklisting should be treated as fully compromised.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.