How the scam operates.
The domain is registered as an internationalised domain name (IDN) using the punycode encoding prefix xn--, a technique that causes certain browsers and link-preview tools to render the address as a near-identical visual copy of a widely used Ethereum wallet service. To a casual observer scanning a URL in a message or search result, nothing appears amiss. The operation targets cryptocurrency holders who believe they are navigating to a familiar, trusted interface.
Victims typically arrive via phishing links seeded through social media posts, sponsored search results, or direct messages. The site presents a convincing replica of the targeted wallet interface, prompting visitors to enter their mnemonic recovery phrase, private key, or login credentials. Any data submitted is transmitted to the operator rather than processed locally. Because recovery phrases grant unconditional access to all associated funds across every device, a single successful capture is sufficient to drain the wallet entirely.
The point of failure is usually discovered only after the victim attempts to access their assets through the genuine service and finds the balance has been transferred. At that stage, the operator has typically moved funds through one or more intermediary addresses, and the phishing domain may already be inactive or replaced. The platform offers no support channel, no operator identity, and no mechanism for dispute or recovery.
Red flags we documented.
- 01Punycode IDN construction signals homograph operationThe xn-- prefix identifies this as an internationalised domain name encoding one or more non-ASCII Unicode characters. This technique is routinely used to register addresses that are visually indistinguishable from trusted domains in browser address bars, link previews, and messaging apps.
- 02No legitimate wallet platform uses punycode addressingEstablished cryptocurrency wallet services operate on plain ASCII domains. A wallet interface accessible only through a punycode address has no credible operational justification, and no legitimate provider directs users to access their funds via such an address.
- 03CryptoScamDB blacklist confirmationThe domain is listed explicitly in the CryptoScamDB community blacklist, a maintained and publicly audited registry of addresses reported in connection with theft and fraud. Independent blacklist inclusion is a reliable signal of confirmed malicious activity.
- 04Seed-phrase harvesting as the operative patternWallet impersonation sites exist for a single purpose: capturing recovery phrases or private keys. Any web-based interface requesting these credentials outside of a locally installed application presents an unacceptable risk, regardless of how the interface appears.
- 05No operator identity or registration transparencyThere are no documented aliases, corporate registrations, regulatory disclosures, or support channels associated with this domain. This absence of verifiable identity is consistent with ephemeral phishing infrastructure designed to be discarded once exposure occurs.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.