How the scam operates.
Esta operação se aproveita do nome e da aparente identidade de um serviço de wallet Ethereum de autocustódia amplamente reconhecido. O domínio incorpora o nome da marca visada de forma quase literal, posicionando o site para capturar visitantes que digitam um URL incorretamente, seguem um link em uma mensagem de phishing ou o encontram por meio de resultados de busca manipulados. O domínio de topo .airforce é o único desvio explícito em relação à marca que imita, um detalhe que usuários desatentos, sob pressão de tempo ou com leve distração, têm boas chances de não perceber.
Operações desse tipo apresentam uma réplica da interface visada e solicitam que os visitantes se autentiquem enviando uma chave privada, seed phrase ou arquivo keystore. Esse é o mecanismo central: a interface não precisa funcionar como uma wallet para ter sucesso. Ela só precisa convencer o usuário a inserir as credenciais uma vez. Essas credenciais são transmitidas ao operador, que pode então acessar as wallets correspondentes de forma independente e no seu próprio tempo. O site pode simular um login bem-sucedido para retardar a suspeita.
As vítimas costumam descobrir a fraude quando encontram o saldo da wallet esvaziado após o que parecia ser um login de rotina. Como as transferências on-chain são irreversíveis, a janela entre o envio das credenciais e a retirada dos fundos costuma ser o único momento em que a intervenção é teoricamente possível, e ela se fecha rapidamente. Quando uma reclamação é registrada, o operador em geral já processou os fundos por meio de endereços adicionais, e a própria infraestrutura de phishing pode já ter sido retirada do ar ou migrada para um novo domínio.
Red flags we documented.
- 01Brand impersonation in the domain nameThe domain reproduces the name of a legitimate, well-established Ethereum wallet service with no meaningful alteration. This is a deliberate tactic: the closer a fraudulent domain sits to a trusted name, the less cognitive effort a victim needs to expend to accept it as genuine.
- 02Anomalous top-level domain for a financial interfaceLegitimate cryptocurrency wallet services operate under conventional TLDs. The use of .airforce for what purports to be a wallet interface has no plausible commercial rationale and is a recognised marker of opportunistic phishing infrastructure assembled quickly and cheaply.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained register of confirmed malicious cryptocurrency addresses and domains. Inclusion indicates the site has been independently identified as a threat by researchers outside CryptoLeek.
- 04Credential-request pattern inconsistent with legitimate wallet operationAny web-based interface that requests a private key or seed phrase to grant wallet access is operating outside the security model of self-custody. Legitimate wallet interfaces of the type being impersonated here do not require server-side submission of these credentials under any normal circumstances.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.