How the scam operates.
O site se apresenta como uma interface legítima de wallet Ethereum, apropriando-se do nome e da reputação implícita de um serviço de wallet bem estabelecido. A superfície operacional, o nome de domínio, o provável design visual e a linguagem voltada ao usuário são construídos para serem indistinguíveis, à primeira vista, da plataforma autêntica. O público-alvo são usuários de Ethereum em busca de acesso à wallet, sobretudo aqueles que chegam por mecanismos de busca, links de redes sociais ou URLs encaminhadas, e não por favoritos digitados.
A mecânica segue o modelo padrão de coleta de credenciais comum às operações de phishing de wallets. Os visitantes são induzidos a inserir uma seed phrase, uma chave privada ou um arquivo keystore sob o pretexto de fazer login ou recuperar o acesso a uma conta. O operador captura essas credenciais no lado do servidor no momento da inserção. Como as chaves privadas de Ethereum concedem controle incondicional e irrevogável sobre os fundos associados, uma única captura bem-sucedida basta para esvaziar todos os ativos mantidos na wallet visada, sem necessidade de qualquer outra ação da vítima.
A falha normalmente só se torna evidente depois que as credenciais já foram enviadas. Os usuários percebem que a interface retorna um erro, redireciona de forma inesperada ou parece funcionar normalmente enquanto um processo paralelo drena a wallet em silêncio. Quando a discrepância é investigada, o operador já moveu os fundos por um ou mais endereços intermediários, tornando o rastreamento on-chain difícil sem ferramentas especializadas. Não existe na plataforma qualquer mecanismo de recuperação ou contestação, pois nenhum jamais foi pretendido.
Red flags we documented.
- 01TLD substitution as impersonation techniqueThe domain replicates the name of a recognised Ethereum wallet service while substituting a different top-level domain. This pattern, known as TLD spoofing, is a deliberate attempt to exploit typographical error and user inattention. Legitimate wallet providers do not operate across multiple conflicting TLDs.
- 02.su TLD registration patternThe .su ccTLD (administered for the former Soviet Union) remains operational and is disproportionately represented in fraud and phishing infrastructure due to minimal registration oversight and enforcement cooperation. Its use here provides no legitimate geographic or operational justification.
- 03CryptoScamDB blacklist confirmationThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained dataset used by wallet software, browser extensions, and security researchers to block known malicious addresses. Inclusion reflects documented community reports, not automated heuristics alone.
- 04Private-key harvest, irreversible loss exposureWallet phishing operations targeting seed phrases or private keys expose victims to total, permanent asset loss. Unlike payment card fraud, there is no chargeback mechanism and no custodial institution to contest with. Any platform requesting a private key or seed phrase outside of a locally-running, verifiable application should be treated as hostile.
- 05Absence of verifiable operational historyOperations of this type typically lack any auditable history, no company registration, no named team, no published security disclosures, and no track record predating the fraud campaign. The use of an impersonation domain further forecloses any legitimate identity claim the operator might otherwise make.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.