NewsCryptoCoinbase Traces $1.1 Million in Crypto Payments as Microsoft Dismantles EvilTokens Phishing Network

Coinbase Traces $1.1 Million in Crypto Payments as Microsoft Dismantles EvilTokens Phishing Network

Author: Crypto Ninjas·

Key Takeaways

  • •Coinbase partnered with Microsoft and security groups to disrupt EvilTokens, an AI-powered phishing-as-a-service platform distributed through Telegram that enabled email account takeovers and payment fraud.
  • •Coinbase's Global Intelligence team identified approximately $1.1 million in EvilTokens revenue between October 2025 and June 2026, tracing more than 1,000 deposits from over 700 crypto addresses on the TRON blockchain.
  • •Microsoft linked the platform to more than 12,000 compromised inboxes across over 10,000 organizations, with targets spanning financial services, healthcare, construction, real estate, and higher education.
  • •The operation, which abused Microsoft's device-code authentication, resulted in 50 seized websites, more than 175 blocked domains, and the arrest of two men by UK police on September 11.
  • •Coinbase stated its own records and customer membership were not infiltrated, though some customers were separately tricked into transferring cryptocurrency to scam-controlled addresses.
Coinbase Traces $1.1 Million in Crypto Payments as Microsoft Dismantles EvilTokens Phishing Network

Coinbase has joined Microsoft and a coalition of security organizations in disrupting EvilTokens, a phishing-as-a-service platform that used artificial intelligence to help criminals compromise email accounts and redirect financial payments, including cryptocurrency. The crypto exchange's role in the operation centered on the financial side of the scheme: tracing the money flowing through the service and identifying users connected to it.

Phishing-as-a-service offerings of this kind package infrastructure, templates, and automation tools that allow even low-skilled criminal customers to run convincing credential-harvesting campaigns. Coinbase announced its participation in the takedown on X on September 22, 2026, and described the collaboration in an official blog post.

We partnered with Microsoft to disrupt EvilTokens, an AI-powered cybercrime platform. Our team joined a global effort to dismantle its operations – investigating infrastructure, taking down domains, and helping police arrest its operators. Say goodbye to another major… pic.twitter.com/myu0II6EwX

— Coinbase 🛡️ (@coinbase) September 22, 2026

Source: Coinbase on X

Coinbase Follows the Crypto Money Trail

EvilTokens operated as a pre-packaged cybercrime service distributed through Telegram. Criminal customers could use its tools to launch phishing campaigns, steal access to email accounts, and comb through compromised mailboxes for information that could be exploited in follow-on fraud.

Payment infrastructure provided Coinbase's entry point into the case. The platform accepted cryptocurrency in exchange for its service and ultimately collected its proceeds through addresses on the TRON blockchain, whose public transaction records made the payment flows traceable.

Between October 2025 and June 2026, Coinbase's Global Intelligence team identified approximately $1.1 million in transactions tied to the platform's revenue, detecting the funds within the exchange's payment stream. Investigators traced more than 1,000 deposits originating from well over 700 different crypto addresses and followed the money from there.

The case reflects a recurring pattern in crypto-related cybercrime investigations: even when perpetrators attempt to move funds across multiple, blockchain transactions can leave investigators a payment trail to follow.

Coinbase said it also examined customers of EvilTokens identified on its platform and notified law enforcement accordingly. The company stated that its own records and customer membership were not infiltrated during the campaign. Some customers were victimized separately, however, after attackers broke into their Coinbase accounts and tricked them into transferring cryptocurrency directly to scam-controlled addresses.

AI Turned Phishing Into a Fraud Pipeline

EvilTokens combined account takeovers with AI-driven analysis. Once its tools gained access to an inbox, they could identify trusted relationships, locate payment-related conversations, and determine which contact would be most effective to impersonate. Security teams refer to this playbook as business email compromise, a fraud pattern in which attackers hijack or pose as trusted correspondents to divert payments.

According to Microsoft, more than 12,000 compromised inboxes across over 10,000 organizations were linked to the platform. Targets spanned industries ranging from financial services to healthcare, construction, real estate, and higher education.

The scheme also abused Microsoft's device-code authentication procedure, a legitimate login method designed for input-constrained devices such as televisions and printers. Victims were directed to fake login pages and prompted to enter codes that were then submitted on Microsoft's legitimate login page, allowing attackers to sign in without ever stealing the victims' passwords.

175+ Domains Disrupted

Microsoft and Health-ISAC, a threat-intelligence sharing group for the healthcare sector, pursued legal action in the U.S. District Court for the Eastern District of Virginia, while Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, TRM Labs, and The Shadowserver Foundation contributed to the broader disruption effort. Coordinated efforts of this kind — court orders paired with contributions from infrastructure, security, and blockchain-analysis firms — have become a common template for disrupting crime-as-a-service platforms.

The operation resulted in the seizure of 50 websites and the blocking of more than 175 domains tied to EvilTokens' infrastructure. UK police also arrested two men on September 11 as part of the investigation, according to Microsoft and Coinbase.

For the cryptocurrency sector, the operation illustrates how on-chain financial intelligence can complement conventional cybersecurity investigations. When digital assets are used to monetize phishing and business email fraud, on-chain analysis can add a financial dimension to conventional investigative work.