
Coinbase has helped uncover the money trail behind EvilTokens, an AI-powered phishing service that was used to target businesses and steal access to email accounts.
The service operated through Telegram and offered tools that allowed criminals to run phishing attacks with less technical knowledge. According to Coinbase, its investigators traced about $1.1 million in payments made to the service between October 2025 and June 2026.
The investigation was carried out with Microsoft and several other technology and security groups. UK police also arrested two men on September 11 in connection with the suspected operation. They were later released on conditional bail while the investigation continues.
EvilTokens was designed as a phishing service that could be rented by other criminals. It used Microsoft's device-code login process to trick victims into giving attackers access to their accounts.
Victims could receive emails that looked like normal business messages, such as invoices, shared documents or voicemail alerts. The emails directed them to fake Microsoft or DocuSign pages and asked them to enter a code on Microsoft's real website.
Once the victim entered the code, attackers could gain an authenticated session without directly stealing the person's password. The attackers could then stay inside the email account and look for useful information.
The service also used AI to study emails and identify important people, payment details and trusted business relationships. This helped criminals find employees who had control over payments and create more targeted messages.
Coinbase's Global Intelligence team followed the cryptocurrency payments made to EvilTokens.
Investigators traced around $1.1 million across four Tron addresses during the investigation period. They also identified more than 1,000 deposits from over 700 different crypto addresses and followed the funds toward their final cash-out points.
Coinbase said the $1.1 million figure represents money paid to the phishing service. It does not represent the total amount stolen from all victims.
The crypto exchange combined blockchain records with other information to help identify the suspected operators and users of the service. Some EvilTokens customers were also identified and referred to law enforcement.
Microsoft took legal action that resulted in the seizure of 50 websites and the shutdown of more than 175 domains connected to the service.
The case shows how AI and cryptocurrency are being used together in modern scams. AI can make phishing attacks easier to prepare and more targeted, while crypto payments can leave a record on public blockchains that investigators may be able to follow.
Coinbase said the operators had also indicated plans to expand the service to target Gmail and Okta accounts, showing that the threat could have moved beyond Microsoft's platforms.