How the scam operates.
This domain uses the Punycode internationalised domain name (IDN) system to construct a web address that renders visually identical to a well-known Ethereum wallet service in most browsers. The underlying domain, when decoded, contains a character substitution invisible to the naked eye in the address bar. The operator presents the site as a trusted self-custody wallet platform, positioned to intercept users who arrive via a mistyped URL, a search result, or a shared phishing link.
The operational model is credential harvesting. Visitors are typically presented with an interface replicating a wallet login or recovery flow, requesting a seed phrase, private key, or keystore file. These three inputs represent the only mechanisms that grant complete control over a cryptocurrency wallet. Once submitted, the information is relayed to the operator, at which point the victim's funds become accessible without further interaction required. The attack requires no malware and leaves no trace on the victim's device.
The breakdown is often delayed by design. Some implementations redirect victims to the genuine service after credential capture, maintaining the illusion of a normal session. Users may not realise anything is wrong until they attempt a transaction and find their balance depleted. By that point, funds have typically moved through one or more intermediate addresses, and the on-chain trail grows cold quickly. There is no mechanism for reversing the transfer; recovery depends on early detection and investigative tracing of the destination wallets.
Red flags we documented.
- 01IDN Homograph Domain PatternThe xn-- Punycode prefix indicates this domain contains a Unicode character substitution designed to mimic a legitimate wallet address. This is a recognised attack technique against cryptocurrency users; no genuine wallet service registers its primary domain in this encoding.
- 02CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of phishing infrastructure. Inclusion follows community review and indicates the domain has been verified as fraudulent by independent researchers.
- 03Seed Phrase Solicitation SignalWallet impersonation platforms of this type invariably request recovery phrases or private keys. No legitimate self-custody wallet requires a user to submit a seed phrase through a web interface to access an existing wallet. Any platform making this request should be treated as hostile.
- 04No Verifiable Operator IdentityThere is no documented corporate registration, regulatory standing, or named operator behind this domain. Legitimate wallet services, whether custodial or non-custodial, maintain transparent organisational identity and are reachable through official channels.
- 05Irreversible Loss ExposureCredential theft of this kind results in on-chain fund transfers that cannot be reversed or disputed. Unlike bank fraud, there is no institutional recourse. Recovery depends entirely on early detection and, in some cases, investigative tracing of destination addresses.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.