How the scam operates.
ドメイン xn--mythrwallt-y7acf.com は、ホモグラフ攻撃を用いて構築された国際化ドメイン名(IDN)です。非ASCIIのUnicode文字を、視覚的に同一に見えるラテン文字に置き換えることで、多くのブラウザのアドレスバー上では、定評のあるセルフカストディ型Ethereumウォレットサービスに属しているかのように見えるアドレスを生成しています。運営者はこのサイトを標準的なウォレットのインターフェースとして見せ、なりすまし対象のサービスの外観を複製することで、検索結果、フィッシングメッセージ、またはソーシャルメディアから誘導されたユーザーを受け入れます。
被害者は通常、フィッシングメール、不正な広告、または正規のサービスに近い順位で表示される検索結果によって誤って誘導され、このサイトにたどり着きます。サイトに到達すると、一見すると通常のログインまたはアカウント復旧の手続きに見えるものが表示され、ウォレットのシードフレーズまたは秘密鍵を入力するよう促されます。このサイトに正当な機能は一切なく、認証情報を提出させることが本作戦の唯一の目的です。入力されたフレーズはサーバー側で記録され、関連するウォレットはその後、多くの場合数分以内に枯渇させられます。
被害が明らかになるのは、被害者がウォレットの資金が消失していること、またはシードフレーズによって正規のサービスへアクセスできなくなっていることに気づいた時点です。その時点ですでに秘密鍵は運営者の管理下にあり、資産は通常、足取りを隠すために中間アドレスを経由して移動されています。ブロックチェーンのフォレンジック調査や、資金が現金化される取引所の協力がなければ、現実的な回収は極めて限定的であり、また本作戦が匿名で行われている性質上、追及すべき特定可能な当事者が残されていません。
Red flags we documented.
- 01IDN homograph constructed to mimic a recognised wallet addressThe domain uses Punycode-encoded Unicode characters to produce a visual clone of a well-established wallet service address. This is a deliberate technical choice with no purpose other than deception; there is no legitimate reason to register a near-identical variant of another service's domain.
- 02Confirmed listing in the CryptoScamDB blacklistCryptoScamDB maintains a community-verified, publicly auditable blacklist of phishing and fraud infrastructure. This domain's presence indicates it has been independently flagged by researchers, not merely suspected on the basis of appearance.
- 03Seed phrase input requested outside a trusted clientAny platform that solicits a wallet seed phrase or private key through a web interface is operating outside established security practice. Self-custody wallet services do not require users to enter recovery phrases on a website under any normal circumstance; such a prompt is the defining signal of a credential-harvesting operation.
- 04No traceable operator, registration, or accountability structurePhishing infrastructure of this kind is typically registered anonymously, hosted on rapidly rotating servers, and carries no verifiable corporate identity, licensing, or complaints mechanism. There is no operator on record and no legitimate channel through which a victim can seek redress directly.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.