Coinbase Intelligence Team Tracks $1.1M in Tron Payments to Phishing-as-a-Service Operation
TREE NEWS reports: Coinbase’s global intelligence team assisted law enforcement in dismantling EvilTokens, a phishing-as-a-service platform that used artificial intelligence to analyze victims’ inboxes and bypass multi-factor authentication through Microsoft device-code login flows. The platform enabled business email compromise and subsequent fund-transfer fraud. Coinbase traced roughly $1.1 million in revenue flowing through four Tron blockchain addresses between October 2025 and June 2026, helping identify both the platform operator and its customers. London’s Metropolitan Police arrested the operator on September 11. Microsoft pursued a civil lawsuit that seized 50 websites and disabled more than 175 related domains.
How the Scheme Worked
EvilTokens exploited a well-known but under-defended weakness: the device-code authentication flow, which was designed for input-constrained devices like smart TVs. Attackers trick victims into entering a legitimate-looking code on Microsoft’s real login page, granting token access without ever needing a password or MFA prompt. Layering AI-driven email analysis on top allowed the operation to craft highly convincing, context-aware lures and to identify high-value targets automatically.
Why This Matters for Crypto
The case illustrates two converging trends. First, phishing-as-a-service has industrialized: criminal tooling is now sold like SaaS, lowering the barrier to entry for ransomware crews and fraud rings. Second, crypto rails — particularly Tron, favored for low fees and high USDT throughput — remain the preferred settlement layer for these operations, giving blockchain analytics a central role in attribution.
- Exchange intelligence teams are increasingly acting as de facto cybercrime investigators.
- On-chain tracing is becoming admissible evidence in cross-border prosecutions.
- Device-code phishing is a systemic identity risk that extends well beyond crypto.
Forward Look
Expect tighter collaboration between exchanges, cloud identity providers, and police forces, plus pressure on Microsoft and peers to harden device-code flows. For crypto firms, the takeaway is that compliance and threat intelligence are merging into a single function. The arrest is a win, but phishing-as-a-service operators adapt quickly — the next iteration is likely already live.




