Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4ffbqa…rh78Summary
An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.
Connected Entities
1 entities · 10 linked investigationsTimeline(4 events)
4 November 2024
CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.
CoinTracking Security Alert30 July 2026
Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.
Crypto.com official X post31 July 2026
Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.
GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls10 August 2026
CoinSpectator publishes an aggregated report citing a Reddit post by user /u/_clickfix_ and linking to a Dark Marc Substack analysis, confirming an active phishing campaign abusing Crypto.com's email infrastructure via SendGrid tracking-domain redirect. One documented victim reports a loss of $50,000 in Bitcoin.
CoinSpectator — Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email DomainDecision Log
- hash: 4MLkWghUQCXYdFubg6vRg7qM1NWm8Vhz57UmWgUbm42Z
- hash: AfU7WwWXCnKcvtPCa6KRXdRwNAcCLLGbrkLpFkv6oQX8
- hash: J4VWMJ1o3fMuvQzouexcZ91SCK6z1XF8rfjXL8Rm64Fn
This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 11:26:22 PM
last updated: 8/25/2026, 10:19:10 AM
4 viewsavoid.net — verified advice for a post-truth world