How the scam operates.
This site presents itself as a legitimate Ethereum wallet portal, deploying a homograph technique to impersonate a well-known wallet interface at the domain level. By substituting one or more ASCII characters with visually identical Unicode equivalents, the operator constructs a domain that renders convincingly in most browsers, targeting users who seek, or are redirected toward, a specific widely-used wallet service. The punycode encoding is invisible to the casual visitor; the displayed address appears trustworthy.
The fraud operates through credential capture. Users who reach the site, whether by mistyped search, phishing link, or redirect, encounter an interface modelled on a familiar wallet product. The site's functional purpose is to solicit the entry of private keys, mnemonic seed phrases, or account credentials. Submission of any such material grants the operator complete and irrevocable control over the associated holdings. No legitimate wallet interface requires a user to enter a seed phrase through a web browser; any site that does is, by structural design, a harvesting operation.
Victims typically discover the compromise after funds have already been moved. The site offers no recourse: once a seed phrase or private key is transmitted, the operator can drain any wallet derived from that credential at any time. Attempts to reach support yield nothing, as these operations carry no genuine customer service function. There is no registered entity, regulatory filing, or verifiable team, which means there is no party to pursue through conventional channels once the loss has occurred.
Red flags we documented.
- 01Wallet connection requested via an unfamiliar domainThe user is asked to connect their wallet to an airdrop site, swap interface, or NFT minting page on a domain that mimics a legitimate project. Once connected, a malicious signature transfers approval to drain assets, often without an obvious prompt.
- 02Urgency framing, "claim within 24 hours"Time pressure is engineered to prevent the user from verifying the URL against the project's official channels. Legitimate airdrops and minting events have multi-day claim windows.
- 03Asks for seed phrase / private keyNo legitimate service ever needs your 12/24-word recovery phrase or private key. Any prompt for these is an active drain attempt, regardless of how legitimate the surrounding page appears.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.