DigitalMoneyBox Signal Desk
DigitalMoneyBox Crypto market intelligence
Browse sections
Security CryptoNinjas

Coinbase Tracks $1.1M Crypto Trail as Microsoft Takes Down 175 EvilTokens Domains

Key Takeaways: Between October 2025 and June 2026, approximately $1.1 million was traced from several Tron addresses belonging to Coinbase for these crypto assets associated with EvilTokens. Over 1,000 deposits from over...

78 /100
Market signal

Watchlist

Published in the last two hours. Multiple named entities are involved.

Coinbase Tracks $1.1M Crypto Trail as Microsoft Takes Down 175 EvilTokens Domains

Key Takeaways:

  • Between October 2025 and June 2026, approximately $1.1 million was traced from several Tron addresses belonging to Coinbase for these crypto assets associated with EvilTokens.
  • Over 1,000 deposits from over 700 crypto addresses were detected in the platform’s payment stream.
  • Microsoft and its partners seized 50 websites and disabled over 175 domains associated with the AI-based phishing attack.

User Score

8.7

Follow us on Google News

Coinbase has joined Microsoft and several security organizations in disrupting EvilTokens, a phishing-as-a-service platform that uses AI to help criminals compromise email accounts and redirect financial payments, including cryptocurrency. The crypto exchange’s role focused on tracing the money behind the operation and identifying users connected to the service.

We partnered with Microsoft to disrupt EvilTokens, an AI-powered cybercrime platform.

Our team joined a global effort to dismantle its operations – investigating infrastructure, taking down domains, and helping police arrest its operators.

Say goodbye to another major… pic.twitter.com/myu0II6EwX

— Coinbase 🛡️ (@coinbase) September 22, 2026

Coinbase Follows EvilTokens’ Crypto Money Trail

EvilTokens is a pre-packaged cybercrime service that is issued via Telegram. Criminal customers can use its tools to launch phishing, steal email access and research an infected mailbox for targeted information.

Payment infrastructure was a key link for Coinbase to crypto. EvilTokens accepted cryptocurrency as a service and would eventually make its money through the addresses of the TRON blockchain.

From Oct. 2025 and up to June 2026, the Global Intelligence team at Coinbase identified some $1.1 million in transactions that generated revenue on Coinbase’s messaging systems; that includes on the platform’s application. Investigators were able to trace over 1,000 deposits from well over 700 different addresses and track the money from there.

Read More: Coinbase Opens $2.2B IPO Door to US Retail Traders in Crypto Exchange Expansion

Crypto Payments Became an Investigative Trail

The case illustrates a common theme in crypto-related cybercrime investigations: blockchain transactions can offer investigators a trail of payments even when the perpetrators try using several wallets.

It added that it also looked at the customers of EvilTokens who are identified on its platform and notified law enforcement accordingly. The company said its records and membership had not been infiltrated during the campaign.

Others, however, were duped by cracking into their Coinbase accounts and tricked into transferring their cryptocurrencies straight to scam addresses.

AI Turned Phishing Into a Crypto Fraud Pipeline

A mix of account takeovers and AI-driven analysis was seen in EvilTokens. After gaining access to an inbox, its tools could determine trusted relationships, find payment-related conversations and uncover who is best to be impersonated.

There were over 12,000 compromised inboxes across over 10,000 organizations connected to the platform, Microsoft reported. It struck industries ranging from financial services to healthcare, construction, real estate and higher education.

It also masqueraded with Microsoft’s device-code authentication procedure. In this way, victims were directed to fake login pages, and codes were entered into Microsoft’s legitimate login page, allowing the attacker to login without stealing the victims’ password.

175+ Domains Disrupted

Microsoft and Health-ISAC pursued legal action in the U.S. District Court for the Eastern District of Virginia, while Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, TRM Labs and The Shadowserver Foundation contributed to the wider disruption effort.

During the operation, it was the seizure of 50 websites as well as blocking of over 175 domains in EvilTokens infrastructure. UK police also arrested two men on September 11 as part of the investigation, according to Microsoft and Coinbase.

For the crypto sector, the operation shows how on-chain financial intelligence can complement conventional cybersecurity investigations when cryptocurrency is used to monetize phishing and business-email fraud.

Read More: Coinbase Targets $24/5 Stock Perps in First U.S. Push for Single-Stock Crypto Futures

The post Coinbase Tracks $1.1M Crypto Trail as Microsoft Takes Down 175 EvilTokens Domains appeared first on CryptoNinjas.

Why this matters

Coinbase is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.

Original source

Read on CryptoNinjas

Related market context