• 6 mins read
  • Published

Coinbase and Microsoft track $1.1 million in crypto to EvilTokens after global phishing bust

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Coinbase and Microsoft track $1.1 million in crypto to EvilTokens after global phishing bust EgonCoin © egoncoin.com
Coinbase and Microsoft track $1.1 million in crypto to EvilTokens after global phishing bust © egoncoin.com

Coinbase and Microsoft followed a $1.1 million crypto trail to EvilTokens, an AI-powered phishing service that broke into over 12,000 inboxes and hit thousands of companies before police shut it down and made arrests in the UK.

Coinbase and Microsoft investigators tracked $1.1 million in crypto payments to EvilTokens, an AI-driven phishing service that broke into more than 12,000 email inboxes around the world. The group targeted over 10,000 companies in finance, healthcare, real estate, and other sectors. The operation ended after a coordinated takedown. Authorities seized 50 websites and shut down more than 150 domains tied to EvilTokens. UK police arrested two men, then released them on conditional bail.

Microsoft said the takedown was approved by the U.S. District Court for the Eastern District of Virginia. The case shows how civil legal action is now being used to disrupt cybercrime infrastructure. The operation brought together Microsoft's Digital Crimes Unit, Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. This level of teamwork across tech and security firms is a new front against AI-powered threats.

EvilTokens leveraged AI at every stage of its phishing attacks, from initial compromise to financial fraud, impacting over 10,000 organizations in just months.

Microsoft Digital Crimes Unit

EvilTokens didn't run like a typical phishing ring. Instead, it sold business email compromise as a subscription. The tools were offered through Telegram. Customers paid $1,500 to start and $500 a month for a package that automated account takeovers, mailbox access, reconnaissance, and AI-powered fraud prep. The service abused Microsoft's device-code authentication-a real sign-in method for hardware like smart TVs-by tricking victims into entering codes on Microsoft's own site. This gave attackers access to mailboxes with real authentication, often slipping past passwords and multifactor checks. Attackers could stay inside company email systems for long stretches.

Once inside, EvilTokens' AI tools sped up the search for financial workflows, pending invoices, and staff with payment authority. The platform could translate and summarize emails, map company hierarchies, and suggest targets for impersonation. This cut down the manual work usually needed for targeted fraud. Microsoft found that EvilTokens' own code was built with AI-assisted development tools, making it easier for both the operators and their customers to use.

The subscription model left a clear money trail. Coinbase's Global Intelligence team tracked about $1.1 million in EvilTokens revenue across four Tron blockchain addresses from October 2025 to June 2026. They found over 1,000 deposits from more than 700 unique addresses, mapping the flow from first payments to cash-outs. These numbers show what EvilTokens took in, not what was stolen from victims. Coinbase combined blockchain data with merchant records, device info, and open-source intelligence to link the platform to its suspected operators. The case was then sent to London's Metropolitan Police. Coinbase also found EvilTokens customers on its own platform and reported them to law enforcement.

The EvilTokens takedown demonstrates how blockchain analytics and cross-sector partnerships can disrupt even sophisticated AI-powered phishing services. By tracing on-chain flows and leveraging legal mechanisms, investigators were able to seize infrastructure and identify suspects, setting a precedent for future cybercrime enforcement.

CoinDeskTier-1 Outlet

Some Coinbase users were tricked into sending crypto to scam addresses after their email threads were compromised. But Coinbase accounts and credentials were not breached. The evidence Coinbase gathered helped Microsoft file civil action against EvilTokens. The takedown came as EvilTokens' operators were reportedly getting ready to expand their toolkit to hit Gmail and Okta accounts.

Microsoft warns that taking down EvilTokens' infrastructure does not remove the core attack method. The company urges organizations to turn off device-code authentication if it's not needed and to tightly control its use elsewhere. For accounts that may be compromised, Microsoft recommends revoking refresh tokens, forcing users to sign in again, and sometimes temporarily disabling the account. Standard session revocation can leave access tokens valid for up to an hour, giving attackers a window to act. Security teams have to weigh the risk of short-term disruption for users against the danger of ongoing unauthorized access.

While shutting down EvilTokens is a win for defenders, the case shows how AI and crypto payments are changing cybercrime. Automating reconnaissance and fraud prep makes it easier for less-skilled attackers. Blockchain payments give both anonymity and a forensic trail. As shown in previous investigations, the mix of AI-driven attacks and on-chain money flows is forcing exchanges, security teams, and police to adapt fast. The EvilTokens case proves that even advanced phishing-as-a-service models can be traced and stopped when crypto payments leave a trail. But the attack methods remain a real risk for companies using device-code authentication or lacking strong session controls.

Microsoft says EvilTokens reached over 10,000 organizations within months of launching, from financial services to construction. The $1.1 million tracked by Coinbase only covers payments to the service, not the total losses to victims. The takedown involved 50 seized websites and more than 150 disabled domains, with police action focused in the UK. Coinbase's probe covered four Tron addresses and found over 1,000 deposits from more than 700 addresses between October 2025 and June 2026.

Device-code authentication was built for hardware that can't use standard browser logins. Now, attackers use it to get around security controls. When a victim enters a code on a real website, they may unknowingly give an attacker control of a session. This can bypass passwords and multifactor checks if the user is already signed in, making it a lasting risk for organizations that don't restrict or monitor its use. Security teams should regularly check authentication flows, session management, and token revocation to cut exposure to these phishing attacks.

Related articles