How the scam operates.
ドメインxn--mythrwallt-lsicf.comは、国際化ドメイン名(IDN)を悪用したホモグラフ型サイトです。「xn--」という接頭辞は、エンコードされた形式の中にUnicode文字が埋め込まれていることを示しており、その結果、多くのブラウザやメッセージングクライアント上で、このドメインは著名な暗号資産ウォレットプラットフォームと視覚的にほぼ同一に表示されます。運営者はこのアドレスを正規のウォレットインターフェースであるかのように見せかけ、フィッシングリンク、検索連動型広告、あるいは緊急性を煽ったり通常のサービス連絡を装ったりするダイレクトメッセージ・キャンペーンを通じて到達する暗号資産保有者を標的としています。
運用上の仕組みは、認証情報およびシードフレーズの窃取です。正規のウォレットサービスに到達したと信じた訪問者には、ログイン画面やウォレットのインポート手続きが提示され、秘密鍵、ニーモニック(復元用フレーズ)、またはアカウントのパスワードの入力を求められます。これらの入力情報は、実在するウォレット基盤によって処理されるのではなく、運営者によって取得されます。このサイトには機能するブロックチェーンのバックエンドは一切不要であり、被害者が見慣れたインターフェースを通じて機密情報を送信するのに十分な時間だけ、この欺瞞が維持されればよいのです。
この詐欺は通常、被害者が正規のサービスを通じて自身の保有資産にアクセスしようとした際に、残高がすでに移転されていることに気づいて初めて明らかになります。差異に気づいた時点では、資産は通常、追跡を困難にする一連の高速なオンチェーンの転送を経て、被害者の管理外のアドレスへと移されています。この手口に基づいて構築されたドメインは、苦情の件数がブラックリストへの掲載を引き起こすと、通常は放棄されるか別のものに切り替えられます。これは、この種のフィッシング業務に共通する使い捨てインフラの手法と一致しています。
Red flags we documented.
- 01Internationalised Domain Name Homograph TechniqueThe xn-- punycode prefix reveals that the domain encodes Unicode characters designed to produce a display string visually indistinguishable from a legitimate service in standard browsers. This technique is a documented method for defeating users' visual domain verification and is associated almost exclusively with credential-theft operations.
- 02CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a maintained open-source registry of addresses associated with cryptocurrency fraud. Inclusion indicates the domain has been independently reported and reviewed by contributors to that project.
- 03Seed Phrase Harvesting Operation PatternSites constructed to mimic wallet interfaces have one primary operational purpose: capturing private keys, mnemonic phrases, or login credentials. No legitimate wallet infrastructure solicits a seed phrase through a web form. Any prompt requesting this material on a lookalike domain should be treated as an active theft attempt.
- 04Disposable Infrastructure SignalHomograph phishing domains are typically registered for short operational windows with no traceable corporate presence, no published terms of service, and no verifiable customer support. The absence of any organisational identity is itself a risk indicator, not merely a neutral omission.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.