How the scam operates.
A operação se apresenta como uma interface legítima de wallet Ethereum, explorando a semelhança visual com um serviço de wallet de criptomoedas amplamente utilizado. Os dois domínios confirmados, myetherwallte.com e myetherwalelt.com, diferem do serviço autêntico apenas por letras transpostas ou inseridas, projetados para interceptar usuários que digitam errado um endereço familiar. O propósito aparente é replicar a interface de uma wallet de autocustódia confiável de forma tão próxima que um visitante desatento não percebe a substituição.
O mecanismo subjacente segue um padrão de phishing bem documentado que tem como alvo detentores de criptomoedas. Os visitantes que chegam ao site, normalmente por meio de uma URL digitada incorretamente ou de um resultado de busca manipulado, deparam-se com uma interface de wallet que solicita sua chave privada, seed phrase ou credenciais de login. Uma vez que esses dados são enviados, o operador obtém acesso completo e irreversível a quaisquer wallets associadas. Transações em blockchain não podem ser revertidas, de modo que a movimentação de ativos a partir de uma wallet comprometida não deixa nenhum caminho prático de recuperação pelos meios convencionais.
O ponto de falha se torna evidente quando a vítima tenta acessar sua wallet legítima e descobre que as credenciais já não funcionam ou que os fundos já foram movimentados sem sua autorização. Operações que seguem esse padrão normalmente agem em poucos minutos após a captura das credenciais, esvaziando as wallets antes que a vítima perceba o que ocorreu. Tentativas posteriores de contato não resultam em nada; a infraestrutura normalmente é abandonada ou rotacionada assim que é sinalizada ou assim que um número suficiente de vítimas passou por ela.
Red flags we documented.
- 01Typosquat Domain ArchitectureBoth confirmed domains are deliberate transpositions of a widely-recognised Ethereum wallet service name. The misspellings require no social engineering beyond exploiting routine typing errors, allowing the operation to harvest victims passively from organic navigation mistakes.
- 02Multiple Alias Domains RegisteredThe operation maintains at least two confirmed alias domains, indicating coordinated infrastructure rather than an isolated incident. Multiple domains extend reach and provide redundancy if one address is taken down or blacklisted by browser security tools.
- 03CryptoScamDB Blacklist InclusionBoth domains appear in the CryptoScamDB community blacklist, referenced by wallet providers and browser extensions to block access to known phishing infrastructure. Inclusion across two separate entries reflects confirmed, community-verified evidence of fraudulent activity.
- 04Credential-Harvesting Platform PatternSites impersonating cryptocurrency wallet interfaces serve a single operational purpose: collecting private keys or seed phrases. No legitimate wallet service solicits these credentials through a web form. Any interface doing so should be treated as hostile regardless of its visual presentation.
- 05No Verifiable Operator or Regulatory StandingThe operation presents no identifiable registered entity, public operator, or regulatory licence. Legitimate wallet services maintain public accountability structures. The absence of any such structure is consistent with the disposable infrastructure typical of short-cycle phishing campaigns.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.