Loading prices…
🔥BULLISH

EvilTokens phishing ring dismantled by Coinbase and Microsoft

On-chain forensics traced $1.1M in months, but the underlying device-code auth vulnerability that powered EvilTokens is already being groomed for Gmail and Okta.

Microsoft and Coinbase helped dismantle EvilTokens, an AI-powered phishing service that compromised more than 12,000 inboxes and reached over 10,000 organizations across financial services, real estate, healthcare and construction. The Telegram-run subscription charged a $1,500 initiation fee plus a $500 recurring fee, and 50 websites plus more than 150 domains tied to the operation were seized in the action.

Why it matters

The case is one of the clearest recent demonstrations of how on-chain forensics can turn a privacy-preserving crime into a traceable one. EvilTokens laundered its subscription revenue across four Tron addresses, but every deposit left a permanent ledger Coinbase could follow backward to the operators and forward to cash-out destinations. That same trail has historically been invisible in fiat banking systems, where subpoena-bound records often lag the money by weeks. The takedown also surfaces a structural vulnerability in Microsoft's device-code authentication flow, designed for smart TVs and conference gear that cannot easily support standard browser logins. Attackers initiated the request themselves, then tricked victims into approving it via phishing emails disguised as invoices and shared files.

Market impact

For crypto, the takedown adds to a growing body of evidence that exchange intelligence teams can produce court-grade attribution in months. Coinbase said its evidence contributed to Microsoft's civil action and to arrests by London's Metropolitan Police on September 11, with two men later released on conditional bail. The exchange also identified EvilTokens purchasers active on its own venue and referred them to law enforcement. Microsoft warned, however, that removing the current infrastructure will not eliminate the method, and that the operators had already signaled plans to extend the toolkit to Gmail and Okta accounts.

Related tokens
$TRX

Frequently asked questions

  1. How did EvilTokens actually compromise Microsoft inboxes?

    Attackers initiated Microsoft's device-code authentication requests themselves, then tricked victims into approving them on Microsoft's legitimate website through phishing emails disguised as invoices, shared files and other routine business communications.

  2. What is device-code authentication and why is it being abused?

    It is a legitimate Microsoft sign-in flow designed for hardware like smart TVs and conference gear that cannot easily support standard browser logins. Attackers abuse it by initiating the request and tricking victims into approving it on the legitimate Microsoft site.

  3. How much did EvilTokens make and how was it traced?

    Coinbase traced about $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, identifying more than 1,000 deposits from over 700 distinct wallets and mapping flows to their eventual cash-out destinations.

  4. Who was arrested in the EvilTokens takedown?

    UK police arrested two men on September 11 on suspicion of offenses connected to the alleged operation. Both were later released on conditional bail pending further investigation.

  5. What does Microsoft recommend to protect against this attack method?

    Microsoft recommends blocking device-code authentication where it is unnecessary and tightly restricting it where operationally required. For suspected compromises, it advises revoking refresh tokens, forcing reauthentication and in some cases temporarily disabling the account.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →