On September 22, Coinbase disclosed that in collaboration with law enforcement and security partners, they dismantled a phishing service platform known as EvilTokens. This platform sold a full set of attack capabilities through a Telegram bot, including email collection, reconnaissance, web email interfaces, and AI automation. The operators also planned to expand the scope of their attacks to Gmail and Okta accounts. The danger of this incident lies not just in the emergence of another set of counterfeit login pages, but in the fact that the attackers entrusted the analysis of relationships after gaining access to users' emails and the selection of payment targets to AI.
According to Coinbase, after EvilTokens accesses the email, AI is used to analyze trusted contacts, identify who has the authority to make payments, and highlight the most likely fraudulent paths. The task that previously required attackers to manually go through a large number of emails has been streamlined into nearly instant target recommendations. Investigators also found that some of the criminal tools are generated using "atmosphere programming" methods, which lowers the barrier for non-professionals to carry out complex business email scams.
From bulk fishing to relationship graph attacks, AI makes phishing more like a precise sales campaign.
Traditional phishing relies on mass sending of fake pages resembling those of exchanges, banks, or wallets, in the hope that a few people will enter their passwords. EvilTokens represents the next phase of this approach. Attackers first obtain access to email accounts, then learn about organizational structures, payment processes, and common language patterns from past communications, and choose to impersonate financial officers, suppliers, or members of management.
This type of attack is more difficult for victims to recognize intuitively. The emails may reference real projects, the correct colleagues, and recent contracts, and the sending times can also fit into daily procedures. Generative AI can also quickly adjust the wording and language, allowing the same set of criminal services to be used in different countries. Security teams can no longer rely solely on spelling mistakes, unfamiliar titles, or fixed templates as criteria for judgment.
"Phishing as a service" further breaks down crime into purchasable modules. Developers are responsible for the tools, data sellers provide email addresses or credentials, and users just need to pay to carry out the attacks. Telegram robots lower the operational barriers, and the web-based email interface allows attackers to manage their targets just like they would with regular SaaS. Shutting down the platform can interrupt a number of attacks, but the code, customers, and infrastructure may be migrated, so a single strike cannot be considered a complete elimination of the threat.
Coinbase has not made public all the details of the investigation or the scale of the impact, nor does it mean that every cryptocurrency user was attacked. What the authorities have disclosed is about the platform's capabilities and the countermeasures taken. In external reports, it should be avoided to describe the 'planned attacks on Gmail and Okta' as if these services have been completely compromised, and it is even more important not to confuse the names of criminal tools with cryptocurrency tokens.
The focus of defense must be extended from login passwords to payment processes and session control.
Multi-factor authentication is still important, but business email scams often take advantage of established sessions, stolen OAuth authorizations, or actions approved by the victims themselves. Enterprises should prioritize the use of anti-phishing Passkey measures or hardware keys, limit outdated authentication methods, monitor new devices, unusual geographical locations, and email forwarding rules, and require re-authentication for high-risk sessions.
The payment process requires independent verification. Any request to temporarily change the recipient's address, supplier's account, or withdrawal destination should be confirmed through known channels other than email. A dual-approval system, amount thresholds, and delay mechanisms make it difficult for attackers to directly complete transfers even if they control one email account. For encrypted assets, an address whitelist and small-scale trial transfers are also of value.
Security teams should also pay attention to the permissions of AI proxies and browser tools. If employees allow assistants to read all emails, automatically generate replies, or perform payments, attackers may exploit prompt injection and contaminated emails to affect the proxies. Minimum permissions, operation previews, manual confirmation of sensitive actions, and complete logging should become the default settings for AI deployments in enterprises.
Platform governance cannot merely involve deleting counterfeit pages. Telegram, domain name registrars, cloud service providers, and encrypted payment channels each hold different pieces of information; only by sharing infrastructure metrics across platforms can the efficiency of combating such issues be improved. When security companies and trading platforms disclose incidents, they should also provide actionable detection rules, rather than merely announcing a "successful closure."
EvilTokens Event description: AI The reduction is not only in the costs of legitimate software development but also in the costs of crime investigation and personalized fraud detection. What is eliminated is a specific service, but what remains is a replicable model. The most effective response for users is not to expect to detect every fake email, but to ensure that no single email address, no single employee, and no single transaction session can independently complete irreversible payments.
Individual users can also perform three low-cost checks: check if there are any unfamiliar forwarding rules in their email accounts, revoke third-party authorizations that are no longer needed, and use different credentials for exchanges, email services, and password managers. When receiving requests from so-called customer service or executives, it is advisable to initiate communication again from the official App or from saved contacts. Attackers are adept at creating a sense of urgency; delaying for a few minutes and confirming through another channel is often safer than continuing to pursue the issue within the original email thread.
Enterprise drills should also assume that email accounts have been compromised, rather than merely testing whether employees will click on links. Only by simulating attackers reading historical emails, establishing rules, and impersonating suppliers can single points of failure in the approval process be exposed. When measuring the effectiveness of defenses, it is important to record how long it takes from an abnormal login to the discovery of the issue, the freezing of payments, and the restoration of accounts.










