Skip to main content
Sign in

Audit log

Every state-changing event for Crypto.com Phishing Campaign — Email Domain Abuse (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-15 23:26:29Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    J4VWMJ1o3fMu…L8Rm64Fnsha256 → base58
    verifying row…
    canonical bytes (20523 B) ▸
    {"actor":"system:backfill","investigation_id":"491937e2-0e11-4c61-ac86-db98727d3bab","kind":"publish","page_slug":"crypto-com-phishing-campaign-email-domain-abuse-august-2026","published_at":"2026-08-15T23:26:29.536Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)","sections":[{"content":"On August 10, 2026, security researchers and the aggregator site CoinSpectator reported an active phishing campaign targeting Crypto.com customers. The original analysis, published on the Substack blog Dark Marc, identified the threat actor as an unknown party that allegedly gained access to Crypto.com's SendGrid marketing account — or a vendor with equivalent access — enabling them to send emails that passed all standard email-authentication checks (SPF: pass, DKIM: pass, DMARC: pass). The responsible threat actor has not been publicly identified, and no law-enforcement charges or regulatory findings had been issued as of the time of this writing. The campaign is treated here as a distinct threat cluster from the Crypto.com exchange itself, which is described as a victim of infrastructure abuse rather than the perpetrator.","heading":"Campaign Overview and Threat Actor","severity":"critical","sources":[{"credibility":3,"name":"Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email Domain — CoinSpectator","type":"news_article","url":"https://coinspectator.com/mainstream/2026/08/10/crypto-com-users-targeted-by-phishing-campaign-abusing-companys-email-domain/"},{"credibility":3,"name":"Dark Marc Substack — Crypto.com Users Targeted by Phishing (primary technical analysis)","type":"research","url":"https://darkmarc.substack.com/p/cryptocom-users-targeted-by-phishing"}]},{"content":"According to the Dark Marc analysis, the campaign exploited SendGrid's click-tracking infrastructure. SendGrid automatically rewrites every link in a customer's outbound email to route through a branded tracking subdomain before forwarding the recipient to the intended URL. In Crypto.com's case the tracking subdomain is url1137.crypto.com, which resolves through SendGrid's servers. The alleged attack chain was: (1) the attacker accessed Crypto.com's SendGrid account — reportedly via stolen credentials or a compromised API key — and composed a malicious email; (2) SendGrid's system rewrote the attacker-controlled destination link to appear as url1137.crypto.com/ls/click?upn=…; (3) that tracking URL silently forwarded clicking recipients to an attacker-controlled page hosted on Google Sites. Because the visible domain in the email was a subdomain of crypto.com and all authentication headers passed, the message bypassed both recipient-side spam filters and corporate email-security gateways. Analysts at IronScales and Netcraft have documented the same SendGrid tracking-domain abuse pattern in prior unrelated campaigns, confirming it is a known and reproducible technique. The Dark Marc report also identified specific evasion artifacts in the August 2026 emails: zero-width Unicode characters embedded in the brand name to defeat pattern-matching filters, a footer copyright date of 2022 (a template artifact left from an older email), a generic 'Dear User' salutation rather than the recipient's name, and a login-event detail citing RFC 5737 IP address 203.0.113.42 — a documentation-only address that no real login would generate.","heading":"Technical Attack Mechanism — SendGrid Tracking Domain Abuse","severity":"critical","sources":[{"credibility":3,"name":"Dark Marc Substack — Crypto.com Users Targeted by Phishing (technical analysis)","type":"research","url":"https://darkmarc.substack.com/p/cryptocom-users-targeted-by-phishing"},{"credibility":2,"name":"Netcraft — Phishception: SendGrid Abused to Host Phishing Attacks","type":"research","url":"https://www.netcraft.com/blog/popular-email-platform-used-to-impersonate-itself"},{"credibility":2,"name":"IronScales — The SendGrid Email That Came From a Window Company","type":"research","url":"https://ironscales.com/threat-intelligence/compromised-domain-sendgrid-brand-impersonation-api-credential-harvest"},{"credibility":3,"name":"Quora — Is url1137.crypto.com likely from a scammer?","type":"community_report","url":"https://www.quora.com/Is-url1137-crypto-com-likely-from-a-scammer"}]},{"content":"The Dark Marc analysis documented one confirmed victim who reported a loss of approximately $50,000 in Bitcoin. The victim had two-factor authentication enabled but entered their one-time code on the attacker's phishing page, which relayed it to Crypto.com's real login endpoint in a real-time credential-relay attack. Funds were drained within minutes of credential entry. Crypto.com has not publicly disclosed aggregate victim counts or total financial losses attributable to this campaign. The absence of an official victim-count disclosure means the $50,000 figure represents a single reported case, not a total loss estimate, and the true scale of harm is unknown.","heading":"Documented Financial Impact","severity":"high","sources":[{"credibility":3,"name":"Dark Marc Substack — Crypto.com Users Targeted by Phishing","type":"research","url":"https://darkmarc.substack.com/p/cryptocom-users-targeted-by-phishing"}]},{"content":"On July 30–31, 2026, Crypto.com posted a warning on its official X (Twitter) account and through other channels alerting users to 'an increase in targeted industry-wide phishing attacks.' The warning specified that Crypto.com will never call users about security issues and will never ask them to transfer funds. It directed users to the Crypto.com Verify tool to authenticate any communications and reminded users that legitimate emails from the platform include the recipient's personal Anti-Phishing Code when that feature has been enabled. One commenter on the announcement noted the warning appeared to come 'twelve hours too late,' suggesting some users had already received fraudulent messages before the public notice. Crypto.com has not announced a breach of its core systems, a compromise of its SendGrid account, or confirmed victim counts. The campaign exploited infrastructure associated with Crypto.com but the company is characterized as the victim of that infrastructure abuse.","heading":"Crypto.com Pre-Warning and Response","severity":"medium","sources":[{"credibility":1,"name":"Crypto.com official X post — July 30, 2026 phishing warning","type":"official","url":"https://x.com/cryptocom/status/2082878997621538848"},{"credibility":1,"name":"Crypto.com Help Center — Anti-Phishing Code","type":"official","url":"https://help.crypto.com/en/articles/5846320-anti-phishing-code"},{"credibility":1,"name":"Crypto.com Verify Tool","type":"official","url":"https://crypto.com/en/verify/"},{"credibility":2,"name":"GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls","type":"research","url":"https://blog.gridinsoft.com/crypto-com-phishing-email-bank-account-alert/"}]},{"content":"The phishing emails reported in this campaign employed urgency-based lures, specifically: false notifications that a new bank account had been added to the victim's Crypto.com profile; claims of an unrecognized login from an unfamiliar location; and demands for immediate identity verification. Some variants reportedly combined the initial email with automated or live follow-up voice calls that added time pressure and further social credibility. These lures are consistent with patterns documented by security analysts at GridinSoft and with Crypto.com's own phishing-recognition guidance. The Dark Marc report noted that even technically proficient victims can be deceived when emails pass authentication checks and arrive in the primary inbox rather than spam folders.","heading":"Social Engineering Lures","severity":"high","sources":[{"credibility":2,"name":"GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls","type":"research","url":"https://blog.gridinsoft.com/crypto-com-phishing-email-bank-account-alert/"},{"credibility":3,"name":"Dark Marc Substack — Crypto.com Users Targeted by Phishing","type":"research","url":"https://darkmarc.substack.com/p/cryptocom-users-targeted-by-phishing"},{"credibility":1,"name":"Crypto.com — How to Recognise Phishing Attempts","type":"official","url":"https://crypto.com/en/crypto/learn/real-life-crypto-phishing-attempts"}]},{"content":"The August 2026 campaign occurred against a backdrop of dramatic growth in AI-assisted crypto impersonation scams. Chainalysis, in its 2026 Crypto Crime Report, found that impersonation scams grew approximately 1,400% year-over-year in 2025, with the average payment into scam clusters rising more than 600% (from approximately $782 to $2,764). Operations with observable connections to AI tooling vendors extracted an average of $3.2 million compared with $719,000 for non-AI operations, operating at roughly 4.5 times greater revenue. Total on-chain scam losses reached at least $14 billion in 2025 and may exceed $17 billion as additional wallets are identified. The FBI's Internet Crime Complaint Center recorded 181,565 cryptocurrency-related complaints with $11.366 billion in attributed losses for 2025, and logged more than 22,000 AI-related complaints for the first time. CryptoDailyUK separately reported in August 2026 that phishing-as-a-service kits enabling these campaigns were priced at approximately $20–$50 per feature tier, lowering the barrier to entry for campaign operators. The SendGrid infrastructure-abuse technique used in the Crypto.com campaign is consistent with the professionalization of phishing operations described in these industry reports.","heading":"Broader Industry Context — AI-Powered Impersonation Surge","severity":"high","sources":[{"credibility":2,"name":"The Next Web — Crypto impersonation scams grew 1,400% as AI supercharged fraud","type":"news_article","url":"https://thenextweb.com/news/crypto-impersonation-scams-1400-percent-ai-deepfake-fraud"},{"credibility":1,"name":"Chainalysis — 2026 Crypto Crime Report: Scams","type":"research","url":"https://www.chainalysis.com/blog/crypto-scams-2026/"},{"credibility":2,"name":"CoinDesk — Chainalysis: Impersonation and AI Scams Are Becoming Crypto's Biggest Threat","type":"news_article","url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"},{"credibility":2,"name":"CryptoDailyUK — AI-Powered Crypto Phishing Changes the Economics of Attacks","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/ai-powered-crypto-phishing-economics"},{"credibility":2,"name":"CoinTelegraph — AI and Impersonation Crypto Scams Experience Record Growth in 2025","type":"news_article","url":"https://cointelegraph.com/news/crypto-scams-2025-ai-impersonation-fraud-chainalysis"}]},{"content":"The attack technique is not without precedent. In November 2024, CoinTracking (a separate portfolio-tracking service) disclosed that an unauthorized actor had accessed its SendGrid marketing account, uploaded an external contact list of approximately 128,000 addresses, and sent phishing emails impersonating the platform using CoinTracking's verified sender domain. The mechanism was structurally identical: because the sending domain was the platform's own authenticated domain, the emails bypassed standard filters. CoinTracking confirmed its core user database and financial data were not compromised. That incident illustrates how access to a SendGrid marketing account — which has lower security requirements than core application credentials — is sufficient to weaponize a brand's domain reputation against its own user base and against third-party recipients whose addresses were harvested elsewhere.","heading":"Precedent — SendGrid Abuse in Crypto Email Infrastructure","severity":"medium","sources":[{"credibility":2,"name":"CoinTracking — Security Alert: Fraudulent Emails Sent via SendGrid","type":"official","url":"https://cointracking.info/blog/unauthorized-sendgrid-email-activity"},{"credibility":2,"name":"FXStreet — Crypto Companies Suffer Supply Chain Email Breach","type":"news_article","url":"https://www.fxstreet.com/cryptocurrencies/news/crypto-companies-suffer-supply-chain-email-breach-users-likely-to-face-series-of-phishing-scams-202406051508"}]},{"content":"The primary fraud indicator for this campaign is the absence of a recipient's personal Anti-Phishing Code in the email body. Crypto.com's Anti-Phishing Code feature — available in both the app and exchange settings — appends a user-chosen string to every legitimate outbound email from Crypto.com. An email that lacks this code, or displays an incorrect one, should be treated as fraudulent regardless of the sending domain. Secondary indicators identified in this campaign include: a generic 'Dear User' salutation instead of the account holder's name; a footer copyright date inconsistent with the email's purported date; zero-width Unicode characters visible in source view; and a login-event IP address that falls within the RFC 5737 documentation range (192.0.2.0/24, 198.51.100.0/24, or 203.0.113.0/24). Crypto.com recommends users navigate to the official app directly rather than clicking any email link, use the Crypto.com Verify tool to authenticate messages, and consider enabling passkeys or FIDO2 hardware keys in place of SMS or OTP-based two-factor authentication, since one-time codes can be relayed in real time by an attacker who has loaded a credential-relay phishing page.","heading":"User Detection and Defense Guidance","severity":"medium","sources":[{"credibility":1,"name":"Crypto.com Help Center — Anti-Phishing Code","type":"official","url":"https://help.crypto.com/en/articles/5846320-anti-phishing-code"},{"credibility":1,"name":"Crypto.com Verify Tool","type":"official","url":"https://crypto.com/en/verify/"},{"credibility":3,"name":"Dark Marc Substack — Crypto.com Users Targeted by Phishing","type":"research","url":"https://darkmarc.substack.com/p/cryptocom-users-targeted-by-phishing"},{"credibility":1,"name":"Crypto.com Help Center — All About Anti-Phishing on Crypto.com App","type":"official","url":"https://help.crypto.com/en/articles/4702792-all-about-anti-phishing-on-crypto-com-app"}]}],"sources_used":[{"credibility":3,"name":"CoinSpectator — Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email Domain","type":"news_article","url":"https://coinspectator.com/mainstream/2026/08/10/crypto-com-users-targeted-by-phishing-campaign-abusing-companys-email-domain/"},{"credibility":3,"name":"Dark Marc Substack — Crypto.com Users Targeted by Phishing","type":"research","url":"https://darkmarc.substack.com/p/cryptocom-users-targeted-by-phishing"},{"credibility":1,"name":"Crypto.com official X post — July 30 2026 phishing warning","type":"official","url":"https://x.com/cryptocom/status/2082878997621538848"},{"credibility":1,"name":"Crypto.com Verify Tool","type":"official","url":"https://crypto.com/en/verify/"},{"credibility":1,"name":"Crypto.com Help Center — Anti-Phishing Code","type":"official","url":"https://help.crypto.com/en/articles/5846320-anti-phishing-code"},{"credibility":1,"name":"Crypto.com Help Center — All About Anti-Phishing on Crypto.com App","type":"official","url":"https://help.crypto.com/en/articles/4702792-all-about-anti-phishing-on-crypto-com-app"},{"credibility":1,"name":"Crypto.com — How to Recognise Phishing Attempts","type":"official","url":"https://crypto.com/en/crypto/learn/real-life-crypto-phishing-attempts"},{"credibility":2,"name":"GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls","type":"research","url":"https://blog.gridinsoft.com/crypto-com-phishing-email-bank-account-alert/"},{"credibility":2,"name":"CryptoDailyUK — AI-Powered Crypto Phishing Changes the Economics of Attacks","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/ai-powered-crypto-phishing-economics"},{"credibility":1,"name":"Chainalysis — 2026 Crypto Crime Report: Scams","type":"research","url":"https://www.chainalysis.com/blog/crypto-scams-2026/"},{"credibility":2,"name":"The Next Web — Crypto impersonation scams grew 1,400% as AI supercharged fraud","type":"news_article","url":"https://thenextweb.com/news/crypto-impersonation-scams-1400-percent-ai-deepfake-fraud"},{"credibility":2,"name":"CoinDesk — Chainalysis: Impersonation and AI Scams Are Becoming Crypto's Biggest Threat","type":"news_article","url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"},{"credibility":2,"name":"CoinTelegraph — AI and Impersonation Crypto Scams Experience Record Growth in 2025","type":"news_article","url":"https://cointelegraph.com/news/crypto-scams-2025-ai-impersonation-fraud-chainalysis"},{"credibility":2,"name":"Netcraft — Phishception: SendGrid Abused to Host Phishing Attacks Impersonating Itself","type":"research","url":"https://www.netcraft.com/blog/popular-email-platform-used-to-impersonate-itself"},{"credibility":2,"name":"IronScales — The SendGrid Email That Came From a Window Company","type":"research","url":"https://ironscales.com/threat-intelligence/compromised-domain-sendgrid-brand-impersonation-api-credential-harvest"},{"credibility":2,"name":"CoinTracking — Security Alert: Fraudulent Emails Sent via SendGrid","type":"official","url":"https://cointracking.info/blog/unauthorized-sendgrid-email-activity"},{"credibility":2,"name":"FXStreet — Crypto Companies Suffer Supply Chain Email Breach","type":"news_article","url":"https://www.fxstreet.com/cryptocurrencies/news/crypto-companies-suffer-supply-chain-email-breach-users-likely-to-face-series-of-phishing-scams-202406051508"},{"credibility":2,"name":"The Cryptonomist — Crypto Security Breaches July 2026","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/14/crypto-security-breaches-july-2026-2/"}],"summary":"An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.","timeline":[{"date":"2024-11-04","event":"CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.","source":"CoinTracking Security Alert","source_url":"https://cointracking.info/blog/unauthorized-sendgrid-email-activity"},{"date":"2026-07-30","event":"Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.","source":"Crypto.com official X post","source_url":"https://x.com/cryptocom/status/2082878997621538848"},{"date":"2026-07-31","event":"Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.","source":"GridinSoft — Crypto.com Phishing Email: Fake Bank Alerts and Calls","source_url":"https://blog.gridinsoft.com/crypto-com-phishing-email-bank-account-alert/"},{"date":"2026-08-10","event":"CoinSpectator publishes an aggregated report citing a Reddit post by user /u/_clickfix_ and linking to a Dark Marc Substack analysis, confirming an active phishing campaign abusing Crypto.com's email infrastructure via SendGrid tracking-domain redirect. One documented victim reports a loss of $50,000 in Bitcoin.","source":"CoinSpectator — Crypto.com Users Targeted by Phishing Campaign Abusing Company's Email Domain","source_url":"https://coinspectator.com/mainstream/2026/08/10/crypto-com-users-targeted-by-phishing-campaign-abusing-companys-email-domain/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 0e82f86c-e2f3-45af-b69f-dc798b36294a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.