Press Enter to search · ESC to close

Regulation

Coinbase Helps Dismantle AI Phishing Platform EvilTokens; Operator Arrested in London

Coinbase's intelligence team helped trace $1.1 million in Tron payments tied to EvilTokens, an AI-powered phishing-as-a-service platform. The operator was arrested in London and Microsoft seized 50 websites, underscoring crypto's central role in both the crime and its prosecution.

Coinbase Intelligence Team Tracks $1.1M in Tron Payments to Phishing-as-a-Service Operation

Coinbase’s global intelligence team assisted law enforcement in dismantling EvilTokens, a phishing-as-a-service platform that used artificial intelligence to analyze victims’ inboxes and bypass multi-factor authentication through Microsoft device-code login flows. The platform enabled business email compromise and subsequent fund-transfer fraud. Coinbase traced roughly $1.1 million in revenue flowing through four Tron blockchain addresses between October 2025 and June 2026, helping identify both the platform operator and its customers. London’s Metropolitan Police arrested the operator on September 11. Microsoft pursued a civil lawsuit that seized 50 websites and disabled more than 175 related domains.

How the Scheme Worked

EvilTokens exploited a well-known but under-defended weakness: the device-code authentication flow, which was designed for input-constrained devices like smart TVs. Attackers trick victims into entering a legitimate-looking code on Microsoft’s real login page, granting token access without ever needing a password or MFA prompt. Layering AI-driven email analysis on top allowed the operation to craft highly convincing, context-aware lures and to identify high-value targets automatically.

Why This Matters for Crypto

The case illustrates two converging trends. First, phishing-as-a-service has industrialized: criminal tooling is now sold like SaaS, lowering the barrier to entry for ransomware crews and fraud rings. Second, crypto rails — particularly Tron, favored for low fees and high USDT throughput — remain the preferred settlement layer for these operations, giving blockchain analytics a central role in attribution.

  • Exchange intelligence teams are increasingly acting as de facto cybercrime investigators.
  • On-chain tracing is becoming admissible evidence in cross-border prosecutions.
  • Device-code phishing is a systemic identity risk that extends well beyond crypto.

Forward Look

Expect tighter collaboration between exchanges, cloud identity providers, and police forces, plus pressure on Microsoft and peers to harden device-code flows. For crypto firms, the takeaway is that compliance and threat intelligence are merging into a single function. The arrest is a win, but phishing-as-a-service operators adapt quickly — the next iteration is likely already live.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback