Coinbase and Microsoft Dismantle AI Phishing Service EvilTokens After Tracing $1.1 Million in Tron Payments

1 hour ago 2 sources neutral

Key takeaways:

  • Tron's role in $1.1M EvilTokens revenue may renew regulatory scrutiny on TRX compliance.
  • Coinbase's security takedown may bolster institutional confidence in crypto infrastructure, outweighing phishing fears near-term.
  • Watch Gmail and Okta expansion as test of crypto's cross-platform security resilience.

Coinbase and Microsoft have led a coordinated takedown of EvilTokens, an AI-powered phishing-as-a-service platform that compromised more than 12,000 inboxes across over 10,000 organizations worldwide. The operation, announced on September 22, 2026, resulted in the seizure of 50 websites and the disabling of more than 175 domains tied to the cybercrime infrastructure.

Coinbase’s Global Intelligence team traced approximately $1.1 million in revenue paid to EvilTokens between October 2025 and June 2026 across four Tron blockchain addresses. Investigators identified more than 1,000 deposits from over 700 distinct crypto addresses and mapped the flow of funds to cash-out destinations. The exchange said it combined transaction data, merchant records, device information and open-source intelligence to help attribute the platform to its alleged operators before referring the case to London’s Metropolitan Police.

Microsoft described EvilTokens as a subscription service sold through Telegram, charging a $1,500 initiation fee and $500 recurring subscription. The toolkit used Microsoft’s device-code authentication flow to trick victims into approving attacker-controlled sessions, then deployed AI to translate and summarize stolen emails, identify payment-related conversations and recommend which employees to impersonate. The service affected sectors including financial services, healthcare, real estate, construction and higher education.

UK police arrested two men on September 11 in connection with the alleged operation, later releasing both on conditional bail. Microsoft and Health-ISAC pursued legal action in the U.S. District Court for the Eastern District of Virginia. Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, TRM Labs and The Shadowserver Foundation contributed to the disruption. Coinbase said its own accounts and credentials were not compromised, though some users were manipulated through compromised email conversations into sending cryptocurrency to scam addresses. Microsoft also warned that EvilTokens’ operator had signaled plans to extend the toolkit to Gmail and Okta.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.