How the scam operates.
Operações como a etherwallet.online se apresentam como interfaces funcionais de carteira Ethereum, explorando a familiaridade visual e nominal com as ferramentas de autocustódia amplamente usadas em todo o ecossistema Ethereum. O domínio é posicionado para parecer confiável em resultados de busca, no preenchimento automático do navegador e em links de phishing distribuídos por redes sociais, e-mail ou plataformas de mensagens. A apresentação na superfície normalmente reproduz o layout e a terminologia de serviços legítimos de carteira de forma fiel o suficiente para passar por uma inspeção superficial.
O modelo operacional segue um padrão de coleta de credenciais. Os visitantes são instruídos a inserir uma chave privada, um arquivo keystore ou uma frase-semente para acessar ou restaurar uma carteira. Essas credenciais são transmitidas para uma infraestrutura controlada pelos operadores, em vez de processadas localmente. Uma vez de posse de uma chave privada, o operador detém acesso irrevogável ao endereço associado e pode transferir todos os saldos sem qualquer ação adicional da vítima. O processo se conclui em segundos, sem nenhum sinal imediato para a vítima.
O engano só se torna evidente depois que os fundos já foram movimentados. As vítimas que enviam credenciais descobrem suas carteiras drenadas em poucos minutos, muitas vezes antes mesmo de sair da página. Como as transações de criptomoedas são irreversíveis por concepção, e como dificilmente os operadores podem ser identificados apenas pelos registros de cadastro do domínio, o recurso convencional fica gravemente limitado. O foco investigativo então se desloca para o rastreamento dos fluxos de saída e a identificação da infraestrutura de exchange ou de mixing que recebeu os ativos.
Red flags we documented.
- 01Domain name mimics established wallet nomenclatureThe domain adopts 'etherwallet' as its core identifier, closely echoing the naming conventions of legitimate self-custody platforms. This pattern is characteristic of typosquatting and brand-impersonation operations designed to capture traffic from users who mistype or misremember a trusted service address.
- 02CryptoScamDB blacklist listingThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained registry of addresses and domains associated with confirmed or credible fraud. Inclusion indicates the domain has been reviewed and flagged by the wider blockchain security community, not merely auto-detected.
- 03Non-standard top-level domain for a wallet-branded platformLegitimate self-custody interfaces are typically hosted on well-established TLDs. The .online TLD combined with wallet-themed branding is a recurring pattern in phishing infrastructure, where operators register low-cost domains to stand up short-lived fraudulent interfaces before abandoning them.
- 04Private-key solicitation is a critical warning signalLegitimate wallet software processes private keys, seed phrases, and keystore files locally on the user's device. Any web interface that transmits these credentials over a network connection is either fraudulent or fundamentally insecure. Victims who enter credentials into such a form should treat the associated address as compromised immediately.
- 05No verifiable organisational identityOperations of this type carry no company registration, no regulatory disclosure, and no traceable team. The absence of these markers, combined with the blacklist listing and impersonation-style domain, is consistent with infrastructure designed for rapid deployment and abandonment rather than sustained, accountable service provision.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.