NewsCryptoCoinbase Traced $1.1 Million in Crypto Payments Behind AI Phishing Service EvilTokens

Coinbase Traced $1.1 Million in Crypto Payments Behind AI Phishing Service EvilTokens

Author: CryptoNewsNet·

Key Takeaways

  • •EvilTokens operated as a Telegram-based subscription service charging a $1,500 initiation fee plus $500 recurring payments for AI-assisted tools covering account compromise, mailbox access, reconnaissance and fraud preparation.
  • •The service abused Microsoft's device-code authentication flow to gain authenticated mailbox access, then used AI to surface pending invoices, wire-transfer conversations and an organization's payment decision-makers for impersonation.
  • •Coinbase's Global Intelligence team traced approximately $1.1 million in platform revenue across four Tron addresses, identifying more than 1,000 deposits from over 700 distinct addresses and mapping flows to cash-out destinations between October 2025 and June 2026.
  • •Microsoft and its partners seized 50 EvilTokens websites and disabled more than 150 related domains, while UK police arrested two men on September 11 who were later released on conditional bail.
  • •Microsoft warned that removing the infrastructure would not eliminate the underlying technique and recommended blocking or tightly restricting device-code authentication, noting that standard session revocation may leave access tokens usable for up to an hour.
Coinbase Traced $1.1 Million in Crypto Payments Behind AI Phishing Service EvilTokens

Coinbase Traced $1.1 Million in Crypto Payments Behind AI Phishing Service EvilTokens

Microsoft and Coinbase have helped dismantle EvilTokens, an AI-powered phishing service linked to more than 12,000 compromised inboxes worldwide, according to details released by the companies.

The operation had reached more than 10,000 organizations within months of launching, spanning financial services, real estate, healthcare, construction and other industries, Microsoft said. The company and its partners seized 50 websites used by EvilTokens and disabled more than 150 related domains. UK police arrested two men on Sept. 11 on suspicion of offenses connected to the alleged operation; both were later released on conditional bail.

A Phishing-as-a-Service Built on AI

EvilTokens packaged much of the business-email-compromise process — a category of fraud in which attackers use compromised or impersonated business email accounts to redirect payments — into a subscription service sold through Telegram. Microsoft said customers paid a $1,500 initiation fee plus a $500 recurring subscription for tools that combined account compromise, mailbox access, reconnaissance and AI-assisted fraud preparation in a single interface.

The service's entry point abused Microsoft's device-code authentication, a legitimate sign-in flow designed for hardware such as smart TVs and conferencing equipment that cannot easily support standard browser logins. Attackers initiated the authentication request themselves, then sent the resulting code to targets through phishing emails disguised as invoices, shared files and other routine business communications. Victims who entered that code on Microsoft's legitimate website effectively approved the session waiting on the attacker's device.

The process could still require a password and multifactor authentication when the user was signed out, but those credentials remained on Microsoft's infrastructure while the procedure generated authorization for the attacker-initiated session. That gave EvilTokens something more useful than a stolen password: an authenticated foothold inside the mailbox.

The platform then automated work that has traditionally required attackers to spend hours reading correspondence and reconstructing how an organization moves money. Its AI tools could translate and summarize messages, identify reporting lines and trusted contacts, surface pending invoices and wire-transfer conversations, and determine which employees had authority over payments. Microsoft said preset prompts could identify an organization's “money movers” and recommend people to impersonate, allowing customers to move from account access to targeted fraud with far less manual reconnaissance.

Investigators also found evidence that parts of EvilTokens were built with AI-assisted coding tools, lowering the technical burden on both sides of the operation. The result was a service that could help less-skilled customers gain access to an account, understand its contents and prepare an impersonation campaign without assembling each capability separately. That structure turned the service into a distribution channel: rather than a single crew running its own attacks, the platform supplied a base of paying customers, extending the same capabilities across many actors.

Crypto Payments Provided Investigators a Trail

The subscription model also generated the financial trail Coinbase used to work backward through the operation. Coinbase's Global Intelligence team traced roughly $1.1 million in EvilTokens platform revenue across four Tron addresses between October 2025 and June 2026. Public blockchain records made that kind of reconstruction possible: transfers between addresses stay permanently visible on the Tron ledger, so analysts can follow funds long after they move. The team identified more than 1,000 deposits from over 700 distinct addresses and mapped flows from payments into EvilTokens through their eventual cash-out destinations. The figures represent revenue paid to the service rather than the amount ultimately stolen from phishing victims.

Coinbase said it combined transaction data with merchant records, device information and open-source intelligence to help attribute the platform to its alleged operators before referring the matter to London's Metropolitan Police. The exchange also investigated EvilTokens purchasers it identified on its own platform and referred those cases to law enforcement. Its evidence contributed to Microsoft's civil action against the service.

Coinbase customers were among those caught downstream. The exchange said some users were manipulated through compromised email conversations into sending cryptocurrency to scam-controlled addresses. Coinbase accounts and credentials, however, were not compromised.

The disruption interrupted an operation that was already looking beyond Microsoft. Coinbase said EvilTokens' operator had signaled plans to extend the toolkit to Gmail and Okta accounts, potentially spreading the same model across other identity platforms. Several threads remain open: the criminal case is at an early stage, with the two arrested men out on conditional bail; Microsoft's civil action proceeds with Coinbase's evidence in hand; and the operator's signaled plans point to Gmail and Okta as the potential next front.

Microsoft Urges Restrictions on Device-Code Authentication

Microsoft warned that removing the service's current infrastructure would not eliminate the underlying method. The company recommends that organizations block device-code authentication where it is unnecessary and tightly restrict it where operationally required. For accounts suspected of compromise, it advises revoking refresh, forcing reauthentication and, in some cases, temporarily disabling the account.

That last step can carry a short-term operational cost, but Microsoft said standard session revocation may leave existing access tokens usable for up to an hour. Attackers have exploited that window in recent campaigns, leaving security teams to choose between brief disruption to legitimate users and continued access for someone already inside the mailbox.

Source: CryptoSlate via CryptoNewsNet