Coinbase traced $1.1 million crypto trail behind AI phishing service EvilTokens
Microsoft and Coinbase helped dismantle EvilTokens, an AI phishing service tied to more than 12,000 compromised inboxes worldwide.
The operation had reached more than 10,000 organizations within months of launching, spanning financial services, real estate, healthcare, construction and other industries, Microsoft said.
The company and its partners seized 50 websites used by EvilTokens and disabled more than 150 related domains, while UK police arrested two men on Sept. 11 on suspicion of offenses connected to the alleged operation. Police later released both on conditional bail.
EvilTokens' phishing service relied on AI use
EvilTokens had packaged much of the business-email-compromise process into a subscription service sold through Telegram. Microsoft said customers paid a $1,500 initiation fee and $500 recurring subscription for tools that combined account compromise, mailbox access, reconnaissance, and AI-assisted fraud preparation in a single interface.
The service's entry point relied on Microsoft's device-code authentication, a legitimate sign-in flow designed for hardware such as smart TVs and conferencing equipment that cannot easily support standard browser logins.
Attackers initiated the authentication request themselves, then sent the resulting code to targets through phishing emails disguised as invoices, shared files, and other routine business communications.
Victims who entered that code on Microsoft's legitimate website effectively approved the session waiting on the attacker's device.
The process could still require a password and multifactor authentication when the user was signed out, but those credentials remained on Microsoft's infrastructure. The process generated authorization for the attacker-initiated session.
That gave EvilTokens something more useful than a stolen password: an authenticated foothold inside the mailbox. The platform then automated work that has traditionally required attackers to spend hours reading correspondence and reconstructing how an organization moves money.
Its AI tools could translate and summarize messages, identify reporting lines and trusted contacts, surface pending invoices and wire-transfer conversations, and determine which employees had authority over payments.
Microsoft said preset prompts could identify an organization's "money movers" and recommend people to impersonate, letting customers move from account access to targeted fraud with far less manual reconnaissance.
Investigators also found evidence that parts of EvilTokens were built with AI-assisted coding tools, lowering the technical burden on both sides of the operation.
The result was a service that could help less-skilled customers gain access to an account, understand its contents, and prepare an impersonation campaign without assembling each capability separately.
Crypto payments gave investigators a trail
The subscription model also created the financial trail Coinbase used to work backward through the operation.
Coinbase's Global Intelligence team traced about $1.1 million in EvilTokens platform revenue across four Tron addresses between October 2025 and June 2026. It identified more than 1,000 deposits from over 700 distinct addresses and mapped flows from payments into EvilTokens through their eventual cash-out destinations. The figures represent revenue paid to the service rather than the amount ultimately stolen from phishing victims.
Coinbase said it combined transaction data with merchant records, device information and open-source intelligence to help attribute the platform to its alleged operators before referring the matter to London's Metropolitan Police.
The exchange also investigated EvilTokens purchasers it identified on its own platform and referred those cases to law enforcement. Its evidence contributed to Microsoft's civil action against the service.
Coinbase customers were also among those caught downstream. The exchange said some users were manipulated through compromised email conversations into sending cryptocurrency to scam-controlled addresses. Coinbase accounts and credentials were not compromised.
The disruption interrupted an operation that was already looking beyond Microsoft. Coinbase said EvilTokens' operator had signaled plans to extend the toolkit to Gmail and Okta accounts, potentially spreading the same model across other identity platforms.
Microsoft warned that removing the service's current infrastructure would not eliminate the method. The company recommends organizations block device-code authentication where it is unnecessary and tightly restrict it where operationally required. For accounts suspected of compromise, it advises revoking refresh tokens, forcing reauthentication and, in some cases, temporarily disabling the account.
That last step can carry a short-term operational cost, but Microsoft said standard session revocation may leave existing access tokens usable for up to an hour. Attackers have exploited that window in recent campaigns, leaving security teams to choose between brief disruption to legitimate users and continued access for someone already inside the mailbox.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Meta's Muse: A Slightly Smarter Version of 'AI Ordering Coffee'

Over 70% of South Korean Crypto Investors Oppose Crypto Tax: What Are Their Concerns?

Ripple’s Schwartz compares Glock case to SEC fight

Hack Coldcard: 52 BTC Saved by Ethical Hackers

Howard Marks: U.S. Fiscal Discipline Out of Control, Buying Bonds to Suppress Yields is Just 'Putting Ice Packs on a Feverish Patient'

BlackRock Redefines Crypto Money for Machines with Bitcoin and Stablecoins

Dubai Authority VARA Enforces Compliance for VASP (Crypto Exchanges)

Bitget Conversations with Trader Shiguang: Seeking the Discrepancy Between Price and Value

IonQ Stock Jumped 12% After Hours: The Company Just Cracked One of Quantum Computing's Hardest Problems
IonQ jumped 12% after hours on a real quantum computing breakthrough, a decoder that fixes errors in real time using nothing more than a standard CPU.

X Sues Two for Fraudulent Acquisition of Creator Rewards, Seeks Return of $278,000

AI and Crypto: Why BlackRock Sees a Major Convergence

Nomura Warns of 'Double Whammy' Risk: The Next Market Storm May Start with Interest Rate Volatility

What is Travix? An on-chain omnibroker combining AI trading and blockchain verification

GME Stock's CEO Just Bought Another $26 Million in Shares: His Stake Just Crossed 40 Million
GameStop's CEO just spent $26.4 million buying more shares, pushing his stake past 40 million. Here's why the timing, and his own compensation structure, make this purchase worth more than a passing headline.

VVV Hits All-Time High: Founder’s Perspective on Models, Privacy, and Crypto

What is PonyGo? An Overview of the Multi-Dimensional Web3 Financial Ecosystem

iPhone App Leads to Crypto Theft of Half a Million Euros - Here's What We Know Now

Strategy Stock's Bitcoin Bet Swung From a $10 Billion Loss to an $8 Billion Profit: Bitcoin Hitting $87K Did It
Strategy's Bitcoin holdings swung from a $10 billion loss to $8.5 billion in profit as BTC briefly touched $87K. Here's the math behind why the stock moves this violently.

Apple and Google Strengthen Talent in Payment and Web3 Strategies, Stablecoin Knowledge Required for Hiring

Bitpace Partners with Fireblocks for Cross-Border Payments with Stablecoins

Hyperliquid open interest reaches record $18 billion: What’s driving activity?
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.

This Cycle May Not Be Led by Bitcoin?

Yield Curve Approaches Inversion, TGA and Fed Tools Become New Focus in US Treasury Market

AI Agent Battle Begins: Amazon Blocks Meta's AI Agent, E-commerce Entry War Escalates
![[Interview] Lee Yun-ho, CEO of KIP: "We need to set the stage before the STO market opens... sharing RWA know-how with financial companies"](/public-static/3_1a7f0699b3.png?format=avif)
[Interview] Lee Yun-ho, CEO of KIP: "We need to set the stage before the STO market opens... sharing RWA know-how with financial companies"

Coinmetrics Report: The Competition of Tokenized Stocks and Their Future Development Path

Transfer of 27,372 ETH: Does FTX Still Have $400 Million in Liquidation Ammo?

In 12 tests, PQLN makes Bitcoin's Lightning Network communication levels resistant to quantum computers




