Coinbase turned detective on an AI phishing ring…
Microsoft's Digital Crimes Unit and Coinbase have dismantled EvilTokens, an AI-powered phishing-as-a-service platform linked to over 12,000 hacked inboxes and $1.1M in Tron-based revenue. Two men were arrested in London.
Inside the EvilTokens Takedown
@Microsoft's Digital Crimes Unit and @coinbase have jointly dismantled EvilTokens, one of the most sophisticated AI-powered phishing platforms seen to date. Emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service platforms, compromising more than 12,000 inboxes across over 10,000 organizations worldwide. The operation was Microsoft Digital Crimes Unit's 40th court-authorized disruption and its first against what it calls an "end-to-end AI-enabled cybercrime service."
At the center of the service was an AI-style chatbot that cybercriminals used to analyze victims' inboxes, identify trusted relationships, payment authorizations, and other sensitive details to facilitate fraud. The service sold access for a $1,500 initiation fee plus a $500 recurring subscription, advertised through a Telegram storefront. Victims were targeted with deceptive emails using 44 different themes, ranging from invoices to file-sharing requests, typically containing malicious URLs, PDFs, or other file types.
Coinbase's Crypto Trail Leads to Arrests
Coinbase's global intelligence team tracked that between October 2025 and June 2026, EvilTokens generated approximately $1.1 million in revenue through four Tron addresses, involving over 1,000 deposits from more than 700 different addresses. That blockchain trail proved critical. The related evidence supported Microsoft's civil lawsuit, ultimately leading to the seizure of 50 websites and the deactivation of over 175 associated domain names.
The action was carried out with authorization from the U.S. District Court for the Eastern District of Virginia and involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. According to Coinbase, at the time of the takedown, the EvilTokens operators were already working on newer phishing tools to target Okta and Gmail accounts.
London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the operation. The two men were arrested on suspicion of making articles for use in fraud and money laundering offenses, and have been released on bail as the investigation continues. Coinbase confirmed no platform credentials were compromised, though some customers were manipulated via email into transferring cryptocurrency to scammer-controlled addresses.
Sources:
Microsoft Security Blog: Unmasking EvilTokens
Fortune: Microsoft and Coinbase probe leads to arrests behind EvilTokens
The Hacker News: Microsoft Takes Down EvilTokens Device-Code Phishing Service
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













