How the scam operates.
Este domínio utiliza o sistema de nome de domínio internacionalizado (IDN) em Punycode para construir um endereço web que, na maioria dos navegadores, é exibido de forma visualmente idêntica a um conhecido serviço de carteira Ethereum. O domínio subjacente, quando decodificado, contém uma substituição de caractere invisível a olho nu na barra de endereços. O operador apresenta o site como uma plataforma confiável de carteira de autocustódia, posicionada para interceptar usuários que chegam por uma URL digitada errado, um resultado de busca ou um link de phishing compartilhado.
O modelo operacional é a coleta de credenciais. Os visitantes geralmente se deparam com uma interface que replica um fluxo de login ou de recuperação de carteira, solicitando uma seed phrase, uma chave privada ou um arquivo keystore. Essas três entradas representam os únicos mecanismos que concedem controle completo sobre uma carteira de criptomoedas. Uma vez enviada, a informação é repassada ao operador, momento a partir do qual os fundos da vítima se tornam acessíveis sem necessidade de qualquer interação adicional. O ataque não exige malware e não deixa rastros no dispositivo da vítima.
A descoberta costuma ser retardada de forma proposital. Algumas implementações redirecionam as vítimas para o serviço genuíno após a captura das credenciais, mantendo a ilusão de uma sessão normal. Os usuários podem não perceber que algo está errado até tentarem uma transação e constatarem que o saldo foi esvaziado. A essa altura, os fundos normalmente já passaram por um ou mais endereços intermediários, e o rastro on-chain esfria rapidamente. Não existe mecanismo para reverter a transferência; a recuperação depende da detecção precoce e do rastreamento investigativo das carteiras de destino.
Red flags we documented.
- 01IDN Homograph Domain PatternThe xn-- Punycode prefix indicates this domain contains a Unicode character substitution designed to mimic a legitimate wallet address. This is a recognised attack technique against cryptocurrency users; no genuine wallet service registers its primary domain in this encoding.
- 02CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of phishing infrastructure. Inclusion follows community review and indicates the domain has been verified as fraudulent by independent researchers.
- 03Seed Phrase Solicitation SignalWallet impersonation platforms of this type invariably request recovery phrases or private keys. No legitimate self-custody wallet requires a user to submit a seed phrase through a web interface to access an existing wallet. Any platform making this request should be treated as hostile.
- 04No Verifiable Operator IdentityThere is no documented corporate registration, regulatory standing, or named operator behind this domain. Legitimate wallet services, whether custodial or non-custodial, maintain transparent organisational identity and are reachable through official channels.
- 05Irreversible Loss ExposureCredential theft of this kind results in on-chain fund transfers that cannot be reversed or disputed. Unlike bank fraud, there is no institutional recourse. Recovery depends entirely on early detection and, in some cases, investigative tracing of destination addresses.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.