How the scam operates.
Esta operação se apresenta por meio de um domínio construído para se parecer com uma conhecida plataforma de wallet Ethereum. A convenção de nomenclatura é um sinal deliberado de falsificação: ela combina a identidade reconhecível de um serviço legítimo de wallet com um sufixo de domínio de topo atípico, uma combinação projetada para passar por uma inspeção superficial enquanto desvia as vítimas do serviço genuíno. O público-alvo são detentores de criptomoedas, em especial aqueles que interagem com ativos baseados em Ethereum e que podem chegar ali por meio de uma URL digitada incorretamente, de um link de phishing ou de um redirecionamento embutido em comunicações fraudulentas.
Operações com esse padrão normalmente apresentam uma réplica visual da interface do serviço legítimo, solicitando que os usuários insiram credenciais sensíveis: chaves privadas da wallet, seed phrases ou senhas de conta. O operador coleta esses dados no lado do servidor. As vítimas não recebem nenhuma mensagem de erro ou indicação imediata de que algo está errado; a interface pode inclusive simular um login ou carregamento de wallet bem-sucedido para retardar a suspeita e impedir denúncias precoces. Como as transações em Ethereum são irreversíveis, a janela entre a captura das credenciais e o esvaziamento dos ativos costuma ser medida em minutos.
A falha se torna evidente quando os usuários tentam movimentar fundos ou acessar a wallet pelo serviço legítimo e descobrem que seus ativos foram esvaziados. Nesse ponto, o domínio fraudulento normalmente está inacessível ou já foi substituído por uma nova variante. As vítimas ficam com um roubo confirmado, sem contraparte a quem recorrer e sem recurso on-chain. O operador já moveu os recursos por meio de saltos adicionais entre wallets, dando início ao processo de ofuscação padrão dessa categoria de operação.
Red flags we documented.
- 01Brand-name impersonation in the domainThe domain incorporates the full name of a well-established Ethereum wallet service verbatim. This is a textbook impersonation pattern: the operator borrows the trust equity of a recognised brand to lower victim suspicion at the point of entry. No legitimate successor, affiliate, or mirror of that service would operate under an unrelated top-level domain.
- 02Anomalous top-level domain signals illegitimacyThe .aetna suffix is a brand-restricted top-level domain associated with a major insurance corporation, not a public or crypto-industry registry. Its appearance in a cryptocurrency wallet URL is structurally incoherent and strongly suggests the domain string was fabricated for use in phishing materials rather than representing a real, publicly accessible web property.
- 03CryptoScamDB blacklist listingThe domain appears in the CryptoScamDB community blacklist, a curated registry of URLs associated with phishing, impersonation, and asset-theft operations in the cryptocurrency space. Inclusion is based on reported malicious behaviour and is a recognised early-warning signal used by wallet providers and browser extensions to block access.
- 04Credential-harvesting architecture patternWallet impersonation sites of this type are engineered specifically to capture private keys or seed phrases, not to provide functional wallet access. Any site that requests these inputs outside of a locally-run, open-source client should be treated as hostile. There is no legitimate operational reason for a web-based interface to solicit a private key directly.
- 05No traceable registration or regulatory footprintThere is no documented regulatory authorisation, company registration, or verifiable operational identity associated with this domain. Legitimate custodial or wallet-adjacent services operating in this space maintain at minimum a public-facing legal identity. The absence of any such record is consistent with an operation designed to be discarded once exposure occurs.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.