Skip to main content
Sign in

Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)

avoid.net/crypto-com-phishing-campaign-email-domain-abuse-august-20263/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.

Have evidence about Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)?

Timeline(4 events)

2024-11-04

CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.

CoinTracking Security Alert

2026-07-30

Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.

Crypto.com official X post

2026-07-31

Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.

GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls

2026-08-10

CoinSpectator publishes an aggregated report citing a Reddit post by user /u/_clickfix_ and linking to a Dark Marc Substack analysis, confirming an active phishing campaign abusing Crypto.com's email infrastructure via SendGrid tracking-domain redirect. One documented victim reports a loss of $50,000 in Bitcoin.

CoinSpectator — Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email Domain
Provenance & Audit Trail
14 Wayback Archives

Decision Log

  • #1publish⛓ pending8/15/2026, 11:26:29 PM
    hash: J4VWMJ1o3fMuvQzouexcZ91SCK6z1XF8rfjXL8Rm64Fn

14 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/15/2026, 11:26:22 PM

last updated: 8/16/2026, 7:16:35 AM

avoid.net — verified advice for a post-truth world