How did Coinbase trace the $1.1 million EvilTokens AI phishing trail?

Coinbase utilized on-chain forensics to track a $1.1 million cryptocurrency trail linked to the 'EvilTokens' phishing service, which uses AI to drain user mailboxes. The investigation reveals how attackers exploit Microsoft authentication flows to steal assets, highlighting a critical new threat to US crypto security in 2026.
How did Coinbase trace the $1.1 million EvilTokens AI phishing trail?

Coinbase successfully traced a $1.1 million cryptocurrency trail by mapping the movement of funds from victims to wallets controlled by the 'EvilTokens' phishing-as-a-service operation. By analyzing transaction patterns on public ledgers, Coinbase's security team identified a cluster of addresses used to aggregate stolen assets, providing a roadmap for law enforcement to potentially freeze these illicit gains. The service marks a significant evolution in cybercrime, combining traditional social engineering with sophisticated automated tools to bypass standard security hurdles.

The technical core of the EvilTokens attack involves the abuse of Microsoft’s legitimate device-login flow. Rather than stealing passwords, the service tricks users into authorizing a persistent session for the attacker. Once access is granted, EvilTokens employs Artificial Intelligence to scan the victim’s entire mailbox history. The AI specifically identifies 'payment authorities'—such as transaction confirmations from major exchanges or private key snippets—allowing the attackers to prioritize and drain high-value crypto accounts with surgical precision.

This discovery comes at a time when US regulators and security agencies are sounding the alarm over AI-augmented financial fraud. The ability of EvilTokens to automate the discovery of crypto-related communications within captured mailboxes suggests that traditional Multi-Factor Authentication (MFA) is no longer a complete defense. For the 2026 market, this incident emphasizes the need for 'AI-vs-AI' security measures, where exchanges use their own machine learning models to detect and block transactions originating from compromised authentication sessions.

Investors and platform users should monitor for updates to OAuth and device-pairing protocols from major service providers like Microsoft and Google. As the EvilTokens trail demonstrates, the speed of AI-driven drainage means that recovery is often impossible once a session is authorized. Moving forward, the industry is expected to shift toward hardware-based signing and more restrictive session management to combat the automated efficiency of modern phishing-as-a-service platforms.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.