Coinbase Helps Take Down Phishing Platform That Bypassed MFA Using AI
A turnkey phishing-as-a-service platform called EvilTokens was taken down by a coordinated effort between technology companies, security organizations, financial institutions, and law enforcement. The platform operated through Telegram bots and allowed anyone to run sophisticated BEC campaigns for a fee.
EvilTokens used AI to map trusted relationships, identify who controlled payments, and flag where fraud was most likely to succeed. This collapsed a process that once required hours of manual inbox sifting into a near-instant automated targeting system.
The platform exploited Microsoft's device code login flow, turning it into an MFA bypass. Victims received convincing emails with malicious links embedded, which led them to fake Microsoft or DocuSign pages displaying a code and instructing them to enter it on Microsoft's real website.
Coinbase customers were among those harmed, as scammers socially engineered them through manipulated emails into sending cryptocurrency to addresses owned by the attackers. The company helped take down EvilTokens by tracing approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026.
The Metropolitan Police arrested the operators on September 11, 2026, seizing digital devices and other items for examination. Coinbase's Global Intelligence team supported Microsoft's civil case, which resulted in the seizure of 50 websites and the disabling of more than 175 domains tied to EvilTokens' infrastructure.