How the scam operates.
The domain xn--yetherwallet-634f.com uses a punycode-encoded internationalised domain name to present as a familiar Ethereum self-custody wallet interface. In browsers that render unicode domain labels without explicit warning, the address bar displays a string visually indistinguishable from a legitimate, long-established wallet service. The site's likely surface presentation mirrors the layout and branding of that recognised platform, targeting Ethereum users who manage their own private keys and are accustomed to web-based wallet interfaces.
The operational model is consistent with credential-harvesting phishing infrastructure. Victims typically arrive via manipulated search results, phishing emails, or social media posts carrying the punycode URL or its decoded visual equivalent. Once on the site, users are prompted to enter their wallet seed phrase, private key, or keystore file under the pretence of accessing or restoring a wallet. Any credentials submitted are transmitted to the operator, who can immediately drain all assets associated with the compromised wallet without further interaction from the victim.
Discovery occurs when the victim attempts to access their legitimate wallet and finds it emptied of funds. Blockchain transactions are irreversible by design, so recovery through the protocol is not possible once assets have been moved. Contact details on the site, if present at all, either return no response or are used to prolong engagement through false promises of resolution, a secondary pattern common to credential-harvesting operations of this type.
Red flags we documented.
- 01Wallet connection requested via an unfamiliar domainThe user is asked to connect their wallet to an airdrop site, swap interface, or NFT minting page on a domain that mimics a legitimate project. Once connected, a malicious signature transfers approval to drain assets, often without an obvious prompt.
- 02Urgency framing, "claim within 24 hours"Time pressure is engineered to prevent the user from verifying the URL against the project's official channels. Legitimate airdrops and minting events have multi-day claim windows.
- 03Asks for seed phrase / private keyNo legitimate service ever needs your 12/24-word recovery phrase or private key. Any prompt for these is an active drain attempt, regardless of how legitimate the surrounding page appears.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.