Cybercriminals are exploiting Punycode, a method for representing Unicode characters in domain names, to create fake URLs that visually mimic legitimate cryptocurrency websites. These lookalike domains trick users into entering private keys or login credentials, leading to stolen funds. For example, attackers may replace Latin characters with similar-looking Cyrillic ones, making malicious sites appear genuine. Victims are often unaware they’re on a fraudulent site. The scam is hard to detect due to browser rendering. Experts urge users to double-check URLs, avoid clicking suspicious links, use bookmarks, and enable anti-phishing tools to protect their crypto assets from these increasingly sophisticated attacks.