How the scam operates.
myetherwallet.info se apresenta como uma interface funcional de wallet Ethereum, mirando usuários que procuram acessar sua wallet ou que digitam errado um endereço conhecido no navegador. O domínio imita de perto o de um provedor de wallet de criptomoedas reconhecido, apoiando-se na semelhança visual entre seu sufixo .info e o consagrado equivalente .com para criar uma impressão de legitimidade. O público-alvo são detentores de Ethereum que já confiam na marca que está sendo falsificada e dificilmente examinam a extensão do domínio.
Operações desse tipo costumam reproduzir o design visual do serviço genuíno com alto grau de precisão, induzindo os visitantes a inserir credenciais da wallet, como chaves privadas, seed phrases ou arquivos keystore, para acessar seus ativos. Como a interface se parece com o produto autêntico, os usuários frequentemente fornecem seu material criptográfico mais sensível sem desconfiar. O operador captura esses dados no lado do servidor e os utiliza para esvaziar as wallets associadas, muitas vezes em questão de minutos após o envio.
O ponto de falha surge quando a vítima tenta concluir uma transação ou consultar um saldo e encontra a interface sem resposta, ou descobre que sua wallet genuína foi esvaziada a partir de um endereço externo que ela não reconhece. A essa altura, o operador já exfiltrou as credenciais. A recuperação de ativos transferidos de uma wallet de autocustódia comprometida é tecnicamente árdua, já que a movimentação é autenticada pela própria chave privada da vítima e, portanto, é indistinguível on-chain de uma transferência voluntária.
Red flags we documented.
- 01Domain Mimics a Recognised Wallet BrandThe .info domain closely replicates a well-established .com wallet address, a pattern consistent with typosquatting designed to intercept users who mistype or follow a malicious link. No affiliation with the original service exists, and the choice of extension appears deliberate.
- 02Listed on CryptoScamDB Community BlacklistThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed malicious cryptocurrency sites. Inclusion reflects prior community-verified harm and is treated by security tooling as grounds for automatic blocking.
- 03Credential Entry Pattern Signals Harvesting OperationWallet impersonation platforms of this type solicit private keys, seed phrases, or keystore files. Legitimate non-custodial wallet interfaces do not require these credentials to be entered on a website under any circumstances. Any platform that does should be treated as hostile.
- 04No Verifiable Operator or Regulatory StandingThe domain carries no documented organisational identity, regulatory authorisation, or verifiable legal presence. Legitimate custodial or financial services are required to disclose these details in most jurisdictions; their absence is a material signal of illegitimacy.
- 05Asset Exposure is Immediate and IrreversibleOnce credentials are submitted to a harvesting operation, the operator can drain associated wallets within minutes. Blockchain transactions are irreversible and carry no chargeback mechanism. The window for any meaningful intervention is extremely narrow.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.