Coinbase Assists in Eliminating EvilTokens: Phishing Tools Start Using AI to Select "The Most Vulnerable Victims"
币界网
3h ago
Ai Focus
On September 22, Coinbase disclosed that in collaboration with law enforcement and security partners, they dismantled a phishing service platform known as EvilTokens. This platform sold a full set of attack capabilities through a Telegram bot, including email collection, reconnaissance, web email interfaces, and AI automation. The operators also planned to expand the scope of their attacks to Gmail and Okta accounts. The danger of this incident lies not just in the emergence of another set of counterfeit login pages, but in the fact that the attackers entrusted the analysis of relationships after invading emails and the screening of payment targets to AI.
Helpful
No.Help

On September 22, Coinbase disclosed that in collaboration with law enforcement and security partners, they dismantled a phishing service platform known as EvilTokens. This platform sold a full set of attack capabilities through a Telegram bot, including email collection, reconnaissance, web email interfaces, and AI automation. The operators also planned to expand the scope of their attacks to Gmail and Okta accounts. The danger of this incident lies not just in the emergence of another set of counterfeit login pages, but in the fact that the attackers entrusted the analysis of relationships after gaining access to users' emails and the selection of payment targets to AI.

According to Coinbase, after EvilTokens accesses the email, AI is used to analyze trusted contacts, identify who has the authority to make payments, and highlight the most likely fraudulent paths. The task that previously required attackers to manually go through a large number of emails has been streamlined into nearly instant target recommendations. Investigators also found that some of the criminal tools are generated using "atmosphere programming" methods, which lowers the barrier for non-professionals to carry out complex business email scams.

From bulk fishing to relationship graph attacks, AI makes phishing more like a precise sales campaign.

Traditional phishing relies on mass sending of fake pages resembling those of exchanges, banks, or wallets, in the hope that a few people will enter their passwords. EvilTokens represents the next phase of this approach. Attackers first obtain access to email accounts, then learn about organizational structures, payment processes, and common language patterns from past communications, and choose to impersonate financial officers, suppliers, or members of management.

This type of attack is more difficult for victims to recognize intuitively. The emails may reference real projects, the correct colleagues, and recent contracts, and the sending times can also fit into daily procedures. Generative AI can also quickly adjust the wording and language, allowing the same set of criminal services to be used in different countries. Security teams can no longer rely solely on spelling mistakes, unfamiliar titles, or fixed templates as criteria for judgment.

"Phishing as a service" further breaks down crime into purchasable modules. Developers are responsible for the tools, data sellers provide email addresses or credentials, and users just need to pay to carry out the attacks. Telegram robots lower the operational barriers, and the web-based email interface allows attackers to manage their targets just like they would with regular SaaS. Shutting down the platform can interrupt a number of attacks, but the code, customers, and infrastructure may be migrated, so a single strike cannot be considered a complete elimination of the threat.

Coinbase has not made public all the details of the investigation or the scale of the impact, nor does it mean that every cryptocurrency user was attacked. What the authorities have disclosed is about the platform's capabilities and the countermeasures taken. In external reports, it should be avoided to describe the 'planned attacks on Gmail and Okta' as if these services have been completely compromised, and it is even more important not to confuse the names of criminal tools with cryptocurrency tokens.

The focus of defense must be extended from login passwords to payment processes and session control.

Multi-factor authentication is still important, but business email scams often take advantage of established sessions, stolen OAuth authorizations, or actions approved by the victims themselves. Enterprises should prioritize the use of anti-phishing Passkey measures or hardware keys, limit outdated authentication methods, monitor new devices, unusual geographical locations, and email forwarding rules, and require re-authentication for high-risk sessions.

The payment process requires independent verification. Any request to temporarily change the recipient's address, supplier's account, or withdrawal destination should be confirmed through known channels other than email. A dual-approval system, amount thresholds, and delay mechanisms make it difficult for attackers to directly complete transfers even if they control one email account. For encrypted assets, an address whitelist and small-scale trial transfers are also of value.

Security teams should also pay attention to the permissions of AI proxies and browser tools. If employees allow assistants to read all emails, automatically generate replies, or perform payments, attackers may exploit prompt injection and contaminated emails to affect the proxies. Minimum permissions, operation previews, manual confirmation of sensitive actions, and complete logging should become the default settings for AI deployments in enterprises.

Platform governance cannot merely involve deleting counterfeit pages. Telegram, domain name registrars, cloud service providers, and encrypted payment channels each hold different pieces of information; only by sharing infrastructure metrics across platforms can the efficiency of combating such issues be improved. When security companies and trading platforms disclose incidents, they should also provide actionable detection rules, rather than merely announcing a "successful closure."

EvilTokens Event description: AI The reduction is not only in the costs of legitimate software development but also in the costs of crime investigation and personalized fraud detection. What is eliminated is a specific service, but what remains is a replicable model. The most effective response for users is not to expect to detect every fake email, but to ensure that no single email address, no single employee, and no single transaction session can independently complete irreversible payments.

Individual users can also perform three low-cost checks: check if there are any unfamiliar forwarding rules in their email accounts, revoke third-party authorizations that are no longer needed, and use different credentials for exchanges, email services, and password managers. When receiving requests from so-called customer service or executives, it is advisable to initiate communication again from the official App or from saved contacts. Attackers are adept at creating a sense of urgency; delaying for a few minutes and confirming through another channel is often safer than continuing to pursue the issue within the original email thread.

Enterprise drills should also assume that email accounts have been compromised, rather than merely testing whether employees will click on links. Only by simulating attackers reading historical emails, establishing rules, and impersonating suppliers can single points of failure in the approval process be exposed. When measuring the effectiveness of defenses, it is important to record how long it takes from an abnormal login to the discovery of the issue, the freezing of payments, and the restoration of accounts.

Tip
$0
Like
0
Save
0
Views 70
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Binance invests $100 million in Circle: Five-year collaboration aims for growth in USDC; does not mean the landscape of stablecoins has been rewritten
Circle and Binance announced an expansion of their cooperation on September 22: Binance made a strategic equity investment of $100 million in Circle, and both parties signed a new five-year business agreement focusing on promoting, integrating, and expanding the use of USDC in emerging markets. Circle will provide the infrastructure services necessary for holding and using USDC, while Binance plans to enhance the visibility of USDC and its product integration within its platform.
币界网
·2026-09-23 09:56:08
69
Canadian cross-border travel in July continues to show divergence: The recovery pace for American tourists and overseas tourists is not the same
Statistics Canada released cross-border travel data for July on September 22: 3.8599 million Canadian residents returned from overseas, a year-on-year increase of 6.9%; 4.5846 million non-resident visitors entered Canada, a year-on-year increase of 7.9%. After seasonal adjustment, 3.6838 million Canadian residents returned, a month-on-month decrease of 0.3%; 2.6283 million non-resident visitors entered, a month-on-month increase of 1.2%. The summer season is usually the peak period of the year, therefore it is necessary to consider the year-on-year and seasonally adjusted month-on-month figures separately.
币百科
·2026-09-23 09:53:50
26
UK borrowed £18.3 billion in August: Higher than predicted for a single month, but a decrease in debt ratio does not mean a lighter burden
In August, the UK's public sector net borrowing reached 18.3 billion pounds, an increase of 2.9 billion pounds from the same period last year, representing a growth of 19%. This figure is also 3.5 billion pounds higher than what was predicted by the Office for Budget Responsibility. Data released by the Office for National Statistics on September 22 also showed that the cumulative borrowing for the fiscal year from April to August amounted to 77.3 billion pounds, which is 2.2 billion pounds less than in the same period last year, but still 8.1 billion pounds higher than official forecasts.
币百科
·2026-09-23 09:52:50
25
Google Challenges with voices in 32 African languages: AI Understand Lingala and Shona; the difficulties are far more than just a lack of data
On September 22nd, Google Research announced the results of the WAXAL speech recognition challenge. WAXAL is an open-source speech dataset that covers 32 African languages. The competition was organized by Google in collaboration with the data science community Zindi. Participants were tasked with building automatic speech recognition systems based on Lingala and Shona. The project aimed to address a long-overlooked issue: millions of people primarily use local dialects in their daily communication, yet mainstream speech AI often fails to understand them.
CoinMeta
·2026-09-23 09:51:39
25
View More