Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)
Summary
An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.
Connected Entities
1 entities · 10 linked investigationsTimeline(4 events)
2024-11-04
CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.
CoinTracking Security Alert2026-07-30
Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.
Crypto.com official X post2026-07-31
Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.
GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls2026-08-10
CoinSpectator publishes an aggregated report citing a Reddit post by user /u/_clickfix_ and linking to a Dark Marc Substack analysis, confirming an active phishing campaign abusing Crypto.com's email infrastructure via SendGrid tracking-domain redirect. One documented victim reports a loss of $50,000 in Bitcoin.
CoinSpectator — Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email DomainDecision Log
- #1publish⛓ pending8/15/2026, 11:26:29 PMhash: J4VWMJ1o3fMuvQzouexcZ91SCK6z1XF8rfjXL8Rm64Fn
14 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 11:26:22 PM
last updated: 8/16/2026, 7:16:35 AM
avoid.net — verified advice for a post-truth world