How the scam operates.
This domain is engineered as a homograph impersonation site. The punycode prefix in its technical address (xn--) signals that the displayed domain name substitutes visually indistinguishable Unicode characters for standard Latin letters, replicating the appearance of a well-known Ethereum wallet interface. Casual inspection of the displayed address offers no reliable visual cue that the domain differs from the legitimate service it mimics. The operator depends entirely on this perceptual ambiguity to draw traffic from users who believe they are accessing a trusted, established platform.
Operations of this type typically reproduce the interface, branding, and user flows of the service being impersonated with considerable fidelity. A victim arriving via a phishing link, a manipulated search result, or a closely typed address is presented with a familiar-looking wallet interface. The site prompts the visitor to enter a private key, seed phrase, or login credentials, framing the request as a routine connection or account-recovery step. These details are transmitted to the operator directly. Any wallet associated with the captured credentials is drained, often within minutes.
Victims typically discover the compromise only after noticing that holdings have been transferred without authorisation, or after their credentials fail on the genuine platform. At that point, the operator has already moved assets to addresses outside the victim's control. Blockchain transactions are irreversible by design, and the operator's infrastructure leaves little recoverable identity data beyond domain registration records and hosting metadata, both of which are frequently falsified or routed through privacy-protective registrars.
Red flags we documented.
- 01Wallet connection requested via an unfamiliar domainThe user is asked to connect their wallet to an airdrop site, swap interface, or NFT minting page on a domain that mimics a legitimate project. Once connected, a malicious signature transfers approval to drain assets, often without an obvious prompt.
- 02Urgency framing, "claim within 24 hours"Time pressure is engineered to prevent the user from verifying the URL against the project's official channels. Legitimate airdrops and minting events have multi-day claim windows.
- 03Asks for seed phrase / private keyNo legitimate service ever needs your 12/24-word recovery phrase or private key. Any prompt for these is an active drain attempt, regardless of how legitimate the surrounding page appears.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.