Skip to content
AI.info

The Pulse

Microsoft and Coinbase Take Down AI Phishing Service EvilTokens

Coinbase says a coordinated operation disrupted EvilTokens, a phishing-as-a-service platform that used AI to analyze compromised inboxes and target cryptocurrency payments.

Microsoft and Coinbase Take Down AI Phishing Service EvilTokens

AI.info Team ·

“If you build, sell, or buy tools to defraud crypto users, we will find you.”

Leah Bressack, Coinbase author

Microsoft and Coinbase helped dismantle EvilTokens, a phishing-as-a-service platform that used artificial intelligence to turn compromised email accounts into ready-made fraud opportunities. Coinbase said on September 22, 2026, that the operation led to the seizure of 50 websites, the disabling of more than 175 related domains and the arrest of alleged operators by the Metropolitan Police in the United Kingdom.

The takedown shows how EvilTokens connected account theft, inbox analysis and payment fraud in one subscription service. Microsoft supported a civil case that produced the infrastructure seizures, while Coinbase followed the cryptocurrency payments and referred suspected operators and customers to law enforcement. Other participants included Health-ISAC, Cloudflare, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs.

EvilTokens turned inbox access into a fraud workflow

EvilTokens operated through Telegram bots and sold access to tools for business email compromise. Coinbase said the platform offered email harvesting, reconnaissance, a built-in webmail interface, access-token use and AI-assisted automation. Its operator was also preparing to expand the service to Gmail and Okta accounts when investigators disrupted it.

The platform exploited Microsoft's device-code login flow. Victims received convincing, AI-generated messages styled as invoices, shared documents or voicemail notifications and were sent to a fake Microsoft or DocuSign page that displayed a login code. They were then directed to enter that code on Microsoft's legitimate website, authorizing an attacker's session and bypassing multifactor authentication.

Once access was obtained, attackers could register devices in Entra ID, create inbox rules designed to hide alerts and delete evidence, and impersonate finance employees, executives or vendors in active payment conversations. Coinbase said the stolen access tokens could survive password resets, giving criminals a way to maintain access after victims changed their credentials.

AI identified the people most likely to approve payments

EvilTokens' defining feature was an AI-powered analyst inside the compromised mailbox. The system mapped trusted relationships, identified who controlled payments and flagged conversations where fraud was most likely to succeed. That reduced a task requiring hours of manual inbox review to a near-instant targeting process.

Attackers could use the resulting intelligence to choose whom to impersonate and which payment thread to enter. The platform also generated phishing messages styled around business documents and routine corporate notices, allowing less experienced criminals to imitate the communications of real employees and suppliers.

Investigators found evidence that parts of EvilTokens were “vibe coded,” meaning the criminals used AI tools to build portions of the service itself. AI therefore assisted both sides of the operation: it helped construct the criminal tooling and helped customers turn stolen mailbox access into targeted fraud.

Coinbase traced $1.1 million through Tron addresses

Coinbase's investigation followed EvilTokens' cryptocurrency payments across the Tron blockchain. The company traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026.

The analysis identified more than 1,000 deposits from over 700 distinct addresses. Coinbase combined transaction data with merchant records, device information and open-source research to attribute the service to suspected operators. The company said Metropolitan Police officers arrested them on September 11, 2026, and seized digital devices and other items for examination.

Coinbase also investigated purchasers who used its platform and referred relevant cases to law enforcement. Its customers were among those harmed by the resulting fraud, although Coinbase said its own accounts and credentials were not compromised. Instead, victims were manipulated through compromised business email accounts into sending cryptocurrency to scam-controlled addresses.

The infrastructure is down, but the technique is not

Coinbase said the disruption removed the EvilTokens infrastructure while criminal investigations continue in the United Kingdom and elsewhere. The operation also gives defenders a clear set of warning signs: unsolicited device-code prompts, unauthorized Entra ID device registrations, hidden inbox rules and payment changes that appear inside otherwise legitimate email threads.

Organizations can reduce exposure by restricting device-code authentication where it is not required, auditing account registrations and verifying payment changes through a known phone number or another independent channel. Coinbase recommends phishing-resistant authentication, including passkeys and hardware security keys.

EvilTokens did not invent device-code phishing or business email compromise. Its importance lies in combining both with automated mailbox analysis and cryptocurrency payment targeting. The seized domains and traced funds show the practical reach of that combination: 50 websites taken down, more than 175 additional domains disabled and about $1.1 million mapped through four Tron addresses.

Source

Coinbase

Explore

More articles