Coinbase Traced $1.1M Through Four Tron Wallets to Kill EvilTokens
A subscription phishing service abused Microsoft's device-code login to breach over 12,000 inboxes worldwide. Coinbase followed the crypto payments and handed the whole thing to London police.
The most effective phishing tool of 2026 didn't crack anything. It used a login flow Microsoft built for smart TVs and conference room screens.
EvilTokens ran for months as a subscription service sold on Telegram. Fifteen hundred dollars to start, five hundred a month after that. Buyers got compromised mailboxes, AI-assisted reconnaissance and a fraud playbook in one interface. Microsoft and Coinbase shut it down, seizing 50 websites and disabling more than 150 domains. UK police arrested two men on Sept. 11 on suspicion of offenses tied to the operation. Both are out on conditional bail.
The entry point is the part worth studying. Device-code authentication exists because a smart TV can't run a normal browser login. Attackers started the session on their own machine, then mailed the code to a target dressed up as an invoice or a shared file. The victim typed it into Microsoft's real website and approved the attacker's waiting session. Multifactor authentication didn't stop it because the credentials never left Microsoft's infrastructure. That's the whole trick. No malware. No stolen password. Just a legitimate flow pointed the wrong way.
From there the AI handled the tedious work. Translating. Summarizing threads. Mapping reporting lines. Surfacing pending wires and figuring out which employee actually signs off on payments. Microsoft says preset prompts could name a company's money movers and suggest who to impersonate. Ten thousand organizations got touched within months. Healthcare, real estate, finance, construction. More than 12,000 inboxes in total.
Coinbase's Global Intelligence team found the money. Roughly $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026. Over 1,000 deposits from 700-plus distinct addresses, traced through to their cash-out destinations. That trail went to London's Metropolitan Police and into Microsoft's civil case. Some Coinbase users got hit downstream too, talked into sending crypto by email threads the attackers had already hijacked.
Here's my take, and it won't sit well with people who share my politics. This is what chain analysis should be for. A $1,500 subscription paid in crypto across hundreds of wallets is a receipt. The chain remembers everything, and this time that's a feature, not the problem. EvilTokens wasn't a privacy tool. It was a burglary franchise with a billing portal. But let's not pretend the tradeoff is free. The same transparency that buried EvilTokens makes life harder for every honest person who just wants to move money without being watched.
Watch the expansion. Coinbase says the operator was already signaling plans to carry the toolkit over to Gmail and Okta. Device-code abuse isn't a Microsoft problem. It's an identity provider problem.
Explore More
Key Terms Explained
In the context of restaking and EigenLayer, an operator is an entity that runs infrastructure to validate AVSs (Actively Validated Services).
A social engineering attack where scammers create fake websites, emails, or messages that look legitimate to steal your credentials or trick you into signing malicious transactions.
Total income generated by a company or protocol before expenses.