Coinbase, Microsoft disrupt Tycoon 2FA phishing network linked to credential theft

ambcryptoPubblicato 2026-03-04Pubblicato ultima volta 2026-03-04

Introduzione

Coinbase, in collaboration with Microsoft, Europol, and other partners, has successfully disrupted the Tycoon 2FA phishing-as-a-service platform. This criminal toolkit enabled attackers to steal login credentials and bypass multi-factor authentication (MFA) by using cloned login pages that mimicked trusted services like Microsoft 365. The operation involved seizing key domains through legal action and dismantling the infrastructure powering the service. Coinbase's investigation traced cryptocurrency payments funding the platform, which operated on a subscription model, and attributed its administration to an individual based in Pakistan. The takedown highlights the significant threat phishing poses to the crypto sector, where social engineering remains a major cause of financial losses. This coordinated effort targeted both the operational infrastructure and the financial networks supporting such cybercrime.

Coinbase said it worked with Microsoft, Europol, and other industry partners to disrupt Tycoon 2FA, a phishing-as-a-service platform used by cybercriminals to steal login credentials and bypass multi-factor authentication [MFA].

The coordinated action targeted infrastructure powering Tycoon’s operations, including domains hosting the platform’s control panels and phishing pages.

According to Coinbase, Microsoft filed a civil action that led to a court-authorized seizure of key domains, effectively taking the service offline.

The effort combined legal action, infrastructure takedowns, and blockchain analysis to trace the financial flows that funded the phishing network.

Phishing platform designed to bypass MFA

Tycoon operated as a subscription-based phishing toolkit, enabling attackers to launch credential-harvesting campaigns using cloned login pages that mimic trusted services such as Microsoft 365 and other widely used platforms.

The platform enabled attackers to capture usernames, passwords, and authentication codes in real time. More critically, it allowed criminals to steal session cookies used to access accounts without triggering MFA prompts.

Security experts say that capability makes phishing campaigns significantly more effective. It turns credential theft into a gateway for broader attacks such as account takeovers, business email compromise, and invoice fraud.

Coinbase traced crypto payments funding the service

Coinbase’s Global Intelligence team said it traced cryptocurrency payments used to fund Tycoon’s operations. Phishing-as-a-service platforms often operate like illicit software businesses, with subscription models, resellers, and recurring revenue streams.

Blockchain analysis helped investigators identify financial connections between the platform’s operators and related infrastructure, according to the company.

The investigation also helped attribute Tycoon’s administration to Saad Fridi, who, Coinbase said, is believed to be based in Pakistan.

Phishing attacks remain a major crypto threat

The disruption comes amid persistent security challenges across the crypto sector.

A recent report showed that crypto-related hacks resulted in $112.53 million in losses across January and February 2026. Incidents were concentrated in a small number of major exploits.

Beyond protocol vulnerabilities, social engineering remains a major driver of losses. This highlights the scale of credential-theft campaigns targeting crypto users and financial platforms.

Platforms like Tycoon have contributed to that trend by industrializing phishing operations, allowing criminals to run campaigns through ready-made toolkits and subscription services.

Pressure on the phishing economy

Coinbase said dismantling services like Tycoon requires targeting both the infrastructure that powers phishing campaigns and the financial networks that support them.

The company said it will continue working with technology companies and law enforcement to prevent cryptocurrency from being used to fund cybercrime.


Final Summary

  • Coinbase and Microsoft helped dismantle Tycoon 2FA, a phishing-as-a-service platform used to steal credentials and bypass MFA protections.
  • The disruption comes as phishing attacks remain a major driver of crypto losses, with security data showing hundreds of millions stolen through social-engineering campaigns.

Domande pertinenti

QWhat is Tycoon 2FA and what was its primary function?

ATycoon 2FA was a phishing-as-a-service platform used by cybercriminals to steal login credentials and bypass multi-factor authentication (MFA) protections.

QWhich companies and organizations collaborated to disrupt the Tycoon 2FA network?

ACoinbase worked with Microsoft, Europol, and other industry partners to disrupt the Tycoon 2FA network.

QHow did the Tycoon 2FA platform manage to bypass multi-factor authentication?

AThe platform allowed attackers to capture usernames, passwords, and authentication codes in real time, and more critically, to steal session cookies which could be used to access accounts without triggering MFA prompts.

QWhat role did Coinbase's Global Intelligence team play in the investigation?

ACoinbase's Global Intelligence team traced the cryptocurrency payments used to fund Tycoon's operations, using blockchain analysis to identify financial connections and help attribute the platform's administration to an individual based in Pakistan.

QAccording to the article, how much was lost to crypto-related hacks in January and February 2026?

AAccording to a recent report cited in the article, crypto-related hacks resulted in $112.53 million in losses across January and February 2026.

Letture associate

SharpLink CEO: How to Understand Ethereum Developers Just Exceeded 1 Million?

SharpLink CEO reflects on the milestone of Ethereum surpassing 1 million historical developers, emphasizing that this figure represents the largest pool of technical talent ever assembled around an open, permissionless blockchain network. While approximately 232,000 developers remain active, the key question for the crypto industry is not which chain is fastest, but where the best builders choose to build long-term. Ethereum's advantage lies in a decade-long accumulation of infrastructure, standards, tools, liquidity, and a cohesive culture, making it the default operating system for programmable finance. This developer base is tackling complex challenges: the Glamsterdam upgrade aims to enhance scalability while preserving core principles; synchronous composability seeks to unify Rollup ecosystems; and significant efforts are underway for post-quantum security. Ethereum's deeper network effects stem from composability and shared standards (like the EVM and Solidity), creating a flywheel of more developers, tools, and liquidity. Three reinforcing strengths cement Ethereum's lead: credible neutrality (secured by ~900k validators), a modular architecture with interconnected Rollups, and a culture that attracts top researchers. The ecosystem is consolidating as the trusted coordination layer for internet-native finance, favored by large institutions valuing security and liquidity. The future of Ethereum is being built by this global community of founders and architects.

链捕手5 min fa

SharpLink CEO: How to Understand Ethereum Developers Just Exceeded 1 Million?

链捕手5 min fa

A Clod of Chinese Soil Chokes Two Japanese Giants

"Chinese Soil Chokes Japanese Giants" The production of a key electronic specialty gas, tungsten hexafluoride (WF6), vital for manufacturing AI chips, was halted by two leading Japanese producers—Kanto Denka and Central Glass. Their shutdown was not due to a technological failure but a sudden, critical shortage of a raw material they had long taken for granted: ultra-high-purity (6N-grade) tungsten powder, which is almost entirely sourced from China. Following a quiet Chinese export announcement in January 2026, tungsten powder shipments to Japan dropped to zero for months. Despite frantic efforts, Japanese companies found no viable alternative; imported powder was three times more expensive and lacked the required purity. Their existing stockpiles were exhausted by mid-2026. WF6 is essential for depositing tungsten into the microscopic contact holes of High Bandwidth Memory (HBM) chips, which are crucial for advanced processors like those from Nvidia. While Japanese firms had mastered producing ultra-pure WF6 gas, their entire supply chain relied on China's 6N tungsten powder—a dependency now revealed as a fatal vulnerability. China's dominance in this "soil" results from decades of painstaking R&D by companies like Xiamen Tungsten and China Tungsten & Hightech. They overcame immense technical hurdles, such as separating chemically similar molybdenum from tungsten, to achieve mass production of the world's purest tungsten powder. With their primary suppliers gone, Kanto Denka and Central Glass announced a permanent halt to WF6 production starting July 1, 2026. This immediately created a supply crisis for major semiconductor manufacturers like Samsung and SK Hynix, forcing them to urgently seek and certify new Chinese suppliers for WF6 itself. The reversal marks a dramatic shift: China has moved from exporting low-value raw materials to controlling the high-purity foundation of a critical global tech supply chain, upending a long-established industrial hierarchy.

marsbit36 min fa

A Clod of Chinese Soil Chokes Two Japanese Giants

marsbit36 min fa

Without Tencent, What's Left for Suiyuan?

The article centers on the crucial question posed in the title: what is Seyond Technology really worth if its dominant customer, Tencent, were to stop purchasing its AI chips? As the last of China's "Four AI Chip Dragons" to secure approval for a public listing, Seyond's IPO filing reveals a profound and controversial dependency. In 2025, 74.9% to over 80% of its revenue came from Tencent. The piece argues that this extreme customer concentration is not merely a vulnerability but a strategic outcome of China's AI industry evolution. It contrasts Seyond's path with its peers (Moore Thread, Biren Technology, and MetaX), noting that while others raced to market with ambitious stories, Seyond focused first on securing and delivering for a major client. Its explosive revenue growth—with Q1 2026 up 1474.85% year-on-year—is driven by concentrated orders from Tencent, which itself faces massive, escalating AI compute demands for products like its Yuanbao and Hunyuan models. The relationship is framed as a deliberate, symbiotic cultivation of a supply chain. As both a major shareholder (20.26%) and primary client, Tencent is actively fostering Seyond to build a controllable, stable alternative to NVIDIA, similar to how global tech giants historically nurtured key suppliers. The high switching costs—involving software stacks and deployed systems—create a deep "ecological moat" for Seyond within Tencent's ecosystem. The analysis positions the AI chip landscape in three tiers: NVIDIA as the global leader, Huawei's Ascend as the state-backed player, and commercial firms like Seyond competing for market orders. Seyond is increasingly seen as "Tencent's compute foundation," with its product roadmap closely aligned with the tech giant's needs. The conclusion is that the industry's metric for success is shifting from fundraising and technical specs to real orders, delivery capability, and ecosystem binding. Seyond's value, therefore, lies not just in its chips but in holding a massive, multi-year procurement order from China's largest internet company—a tangible asset arguably more telling than any technical whitepaper in the current climate. The core insight is that for domestic chips, the ultimate challenge isn't just catching up technologically with NVIDIA, but earning the trust, scenarios, and recurring orders from a major anchor client.

marsbit1 h fa

Without Tencent, What's Left for Suiyuan?

marsbit1 h fa

Trading

Spot
Futures
活动图片