Skip to main content
Sign in

Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)

avoid.net/crypto-com-phishing-campaign-email-domain-abuse-august-20260/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4ffbqa…rh78

Summary

An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.

Have evidence about Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)?

Timeline(4 events)

4 November 2024

CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.

CoinTracking Security Alert

30 July 2026

Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.

Crypto.com official X post

31 July 2026

Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.

GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls

10 August 2026

CoinSpectator publishes an aggregated report citing a Reddit post by user /u/_clickfix_ and linking to a Dark Marc Substack analysis, confirming an active phishing campaign abusing Crypto.com's email infrastructure via SendGrid tracking-domain redirect. One documented victim reports a loss of $50,000 in Bitcoin.

CoinSpectator — Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email Domain
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/15/2026, 11:26:22 PM

last updated: 8/25/2026, 10:19:10 AM

4 views

avoid.net — verified advice for a post-truth world