How the scam operates.
ドメイン xn--mythrwallet-srbc.com はPunycodeでエンコードされたアドレスであり、一部のブラウザやメッセージングアプリケーションで表示された際には、著名なEthereumのセルフカストディ型ウォレットのインターフェースをほぼ寸分違わず再現したものとして映ります。運営者の戦略は明らかに、当該インターフェースへアクセスしようとする利用者や、これを検索する利用者を横取りし、URLのエンコードを精査する理由を持たない利用者に対して、その認証情報入力画面を巧妙に模した画面を提示することにあります。
この詐欺の仕組みは、ホモグラフ攻撃に依拠しています。標準的なラテン文字と視覚的に区別がつかないUnicode文字を含むドメインを登録することで、運営者は人間の目には正規に見えながらも、まったく異なるサーバーに解決されるURLを作り出します。訪問者は通常、リカバリーフレーズや秘密鍵の入力を求めるウォレットアクセス用のインターフェースを提示されます。これらの情報を入力すると、運営者は関連するすべてのウォレットおよびそこに保管された全資金に対して、完全かつ取り消し不能な支配権を握ることになります。
この詐欺が表面化するのは、ウォレットの資金が抜き取られた後になってからです。暗号資産の取引は設計上不可逆であるため、いったんシードフレーズが漏えいすれば、被害者がネットワーク自体を通じて救済を得る手段はありません。運営者は資金の抜き取り後に姿を消すのが通例であり、サポート窓口も、追跡可能な身元も、プラットフォームを通じて回復を求めうる仕組みも残されていません。
Red flags we documented.
- 01Punycode encoding signals deliberate visual impersonationThe xn-- prefix indicates Punycode encoding, a technique routinely exploited to register Unicode lookalike addresses. Legitimate wallet services do not operate through Punycode-encoded domains. The presence of this encoding pattern is itself a strong indicator of deceptive intent rather than any technical necessity.
- 02Confirmed listing on CryptoScamDB blacklistThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of confirmed fraudulent cryptocurrency addresses. Inclusion indicates that independent researchers identified this domain as actively harmful prior to this review, providing corroborating external evidence.
- 03Credential-harvesting pattern with no legitimate use caseHomograph domains in the cryptocurrency sector serve no legitimate operational purpose. The technical effort required to register and deploy a Punycode lookalike is consistent solely with deceiving users into surrendering seed phrases or private keys to an operator they believe to be a trusted service.
- 04Anonymous operation with no verifiable regulatory presenceOperations of this type carry no verifiable company registration, no regulatory licence, and no auditable operational history. The anonymous and ephemeral nature of the setup is consistent with a hit-and-run extraction operation rather than any form of legitimate financial service.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.