Coinbase, Microsoft disrupt Tycoon 2FA phishing network linked to credential theft

ambcryptoPubblicato 2026-03-04Pubblicato ultima volta 2026-03-04

Introduzione

Coinbase, in collaboration with Microsoft, Europol, and other partners, has successfully disrupted the Tycoon 2FA phishing-as-a-service platform. This criminal toolkit enabled attackers to steal login credentials and bypass multi-factor authentication (MFA) by using cloned login pages that mimicked trusted services like Microsoft 365. The operation involved seizing key domains through legal action and dismantling the infrastructure powering the service. Coinbase's investigation traced cryptocurrency payments funding the platform, which operated on a subscription model, and attributed its administration to an individual based in Pakistan. The takedown highlights the significant threat phishing poses to the crypto sector, where social engineering remains a major cause of financial losses. This coordinated effort targeted both the operational infrastructure and the financial networks supporting such cybercrime.

Coinbase said it worked with Microsoft, Europol, and other industry partners to disrupt Tycoon 2FA, a phishing-as-a-service platform used by cybercriminals to steal login credentials and bypass multi-factor authentication [MFA].

The coordinated action targeted infrastructure powering Tycoon’s operations, including domains hosting the platform’s control panels and phishing pages.

According to Coinbase, Microsoft filed a civil action that led to a court-authorized seizure of key domains, effectively taking the service offline.

The effort combined legal action, infrastructure takedowns, and blockchain analysis to trace the financial flows that funded the phishing network.

Phishing platform designed to bypass MFA

Tycoon operated as a subscription-based phishing toolkit, enabling attackers to launch credential-harvesting campaigns using cloned login pages that mimic trusted services such as Microsoft 365 and other widely used platforms.

The platform enabled attackers to capture usernames, passwords, and authentication codes in real time. More critically, it allowed criminals to steal session cookies used to access accounts without triggering MFA prompts.

Security experts say that capability makes phishing campaigns significantly more effective. It turns credential theft into a gateway for broader attacks such as account takeovers, business email compromise, and invoice fraud.

Coinbase traced crypto payments funding the service

Coinbase’s Global Intelligence team said it traced cryptocurrency payments used to fund Tycoon’s operations. Phishing-as-a-service platforms often operate like illicit software businesses, with subscription models, resellers, and recurring revenue streams.

Blockchain analysis helped investigators identify financial connections between the platform’s operators and related infrastructure, according to the company.

The investigation also helped attribute Tycoon’s administration to Saad Fridi, who, Coinbase said, is believed to be based in Pakistan.

Phishing attacks remain a major crypto threat

The disruption comes amid persistent security challenges across the crypto sector.

A recent report showed that crypto-related hacks resulted in $112.53 million in losses across January and February 2026. Incidents were concentrated in a small number of major exploits.

Beyond protocol vulnerabilities, social engineering remains a major driver of losses. This highlights the scale of credential-theft campaigns targeting crypto users and financial platforms.

Platforms like Tycoon have contributed to that trend by industrializing phishing operations, allowing criminals to run campaigns through ready-made toolkits and subscription services.

Pressure on the phishing economy

Coinbase said dismantling services like Tycoon requires targeting both the infrastructure that powers phishing campaigns and the financial networks that support them.

The company said it will continue working with technology companies and law enforcement to prevent cryptocurrency from being used to fund cybercrime.


Final Summary

  • Coinbase and Microsoft helped dismantle Tycoon 2FA, a phishing-as-a-service platform used to steal credentials and bypass MFA protections.
  • The disruption comes as phishing attacks remain a major driver of crypto losses, with security data showing hundreds of millions stolen through social-engineering campaigns.

Domande pertinenti

QWhat is Tycoon 2FA and what was its primary function?

ATycoon 2FA was a phishing-as-a-service platform used by cybercriminals to steal login credentials and bypass multi-factor authentication (MFA) protections.

QWhich companies and organizations collaborated to disrupt the Tycoon 2FA network?

ACoinbase worked with Microsoft, Europol, and other industry partners to disrupt the Tycoon 2FA network.

QHow did the Tycoon 2FA platform manage to bypass multi-factor authentication?

AThe platform allowed attackers to capture usernames, passwords, and authentication codes in real time, and more critically, to steal session cookies which could be used to access accounts without triggering MFA prompts.

QWhat role did Coinbase's Global Intelligence team play in the investigation?

ACoinbase's Global Intelligence team traced the cryptocurrency payments used to fund Tycoon's operations, using blockchain analysis to identify financial connections and help attribute the platform's administration to an individual based in Pakistan.

QAccording to the article, how much was lost to crypto-related hacks in January and February 2026?

AAccording to a recent report cited in the article, crypto-related hacks resulted in $112.53 million in losses across January and February 2026.

Letture associate

US Stock Market Trend (June 16): SpaceX Rises 42% in Two Days, New Fed Chairman Takes Office Today

**U.S. Stocks Trend (June 16): SpaceX Soars 42% in Two Days, New Fed Chair Takes Office Today** Markets surged on Monday following former President Trump's social media announcement of a completed U.S.-Iran deal to reopen the Strait of Hormuz, pending a June 19 signing. The news triggered a broad risk-on rally: oil prices crashed, tech stocks soared, bond yields fell, and defensive sectors lagged. **Market Performance:** The Nasdaq jumped 3.07%, led by semiconductor stocks like Micron (+9.2%). The S&P 500 gained 1.65%, and the Dow rose 0.92% to a record high. However, the Russell 2000 small-cap index underperformed (+0.72%). SpaceX continued its hot streak, rising another 5% pre-market after disclosures of large buys by an Australian billionaire and Cathie Wood's ARK. Boeing also rallied on the transportation optimism. Conversely, energy stocks like Chevron fell over 3% on the oil price plunge, with other defensive sectors also selling off. The day's action showed a clear rotation of funds from energy/defensive plays into AI and tech narratives. **Macro & Outlook:** The VIX fear index fell 8.37%. Treasury yields declined, and WTI crude dropped over 5%. Attention now shifts to a packed schedule: the Bank of Japan is widely expected to hike rates to 1.0% on Tuesday. The Fed's June meeting concludes Wednesday, marking new Chair Wash's debut. While rates are expected to hold, his tone on stubborn inflation and the "dot plot" will be crucial for gauging the 2024 rate path. The formal Iran deal signing is set for Friday. **Trend Perspective:** While the peace deal is a genuine positive, Monday's explosive rally may have gotten ahead of itself, pricing in a swift resolution to inflation concerns. The shortened trading week faces a triple test: BoJ tightening, the Fed's policy stance, and deal implementation details. Tech and semiconductors, which led the surge, remain vulnerable to any disappointment from these key events. The real price discovery begins with the central banks' communications this week.

marsbit21 min fa

US Stock Market Trend (June 16): SpaceX Rises 42% in Two Days, New Fed Chairman Takes Office Today

marsbit21 min fa

Xiaohongshu's Second Great Voyage, This Time Sailing Towards AI

Xiaohongshu's Second Voyage: Navigating Towards AI Since ChatGPT's emergence, Xiaohongshu's founder Mao Wenchao has been acutely aware of AI's potential threat, recognizing that the life advice people seek from chatbots overlaps directly with his platform's core business. Founded in 2013 as a PDF shopping guide for Chinese tourists, Xiaohongshu evolved into a massive community where millions share authentic, personal experiences—from product reviews to travel tips. This vast repository of "I've tried this" human judgment became its most valuable asset. However, the rise of AI, which delivers instant answers, challenges the very need for users to sift through numerous personal notes. Fearing its treasure trove of lived experience could become mere training data for others, Xiaohongshu is proactively adapting. In 2026, it established a dedicated AI division (Dots), launched RED Skill to turn user experiences into usable AI tools, and acquired the AI search product "Diandian." Its investments now extend to AI firms like MiniMax and hardware startups, moving upstream to address needs before they even become search queries. The platform's commercialization strategy is also evolving. With a newly acquired payment license and tools like the AIPS model to track consumer decision journeys, Xiaohongshu aims to seamlessly integrate recommendations with transactions, embedding commerce within AI-generated answers. Yet, a critical tension remains. While building smarter machines to organize and leverage its human experiences, Xiaohongshu must prevent AI from drowning out the authentic, flawed, and trustworthy "I've tried this" voices that built its community. Its core challenge is to harness AI's power without letting the map—the machine's perfect, synthesized answer—replace the territory of genuine human experience. This balance between technological advancement and preserving human trust defines its current journey and its future.

marsbit53 min fa

Xiaohongshu's Second Great Voyage, This Time Sailing Towards AI

marsbit53 min fa

SharpLink CEO: How to Understand Ethereum Developers Just Exceeded 1 Million?

SharpLink CEO reflects on the milestone of Ethereum surpassing 1 million historical developers, emphasizing that this figure represents the largest pool of technical talent ever assembled around an open, permissionless blockchain network. While approximately 232,000 developers remain active, the key question for the crypto industry is not which chain is fastest, but where the best builders choose to build long-term. Ethereum's advantage lies in a decade-long accumulation of infrastructure, standards, tools, liquidity, and a cohesive culture, making it the default operating system for programmable finance. This developer base is tackling complex challenges: the Glamsterdam upgrade aims to enhance scalability while preserving core principles; synchronous composability seeks to unify Rollup ecosystems; and significant efforts are underway for post-quantum security. Ethereum's deeper network effects stem from composability and shared standards (like the EVM and Solidity), creating a flywheel of more developers, tools, and liquidity. Three reinforcing strengths cement Ethereum's lead: credible neutrality (secured by ~900k validators), a modular architecture with interconnected Rollups, and a culture that attracts top researchers. The ecosystem is consolidating as the trusted coordination layer for internet-native finance, favored by large institutions valuing security and liquidity. The future of Ethereum is being built by this global community of founders and architects.

链捕手1 h fa

SharpLink CEO: How to Understand Ethereum Developers Just Exceeded 1 Million?

链捕手1 h fa

A Clod of Chinese Soil Chokes Two Japanese Giants

"Chinese Soil Chokes Japanese Giants" The production of a key electronic specialty gas, tungsten hexafluoride (WF6), vital for manufacturing AI chips, was halted by two leading Japanese producers—Kanto Denka and Central Glass. Their shutdown was not due to a technological failure but a sudden, critical shortage of a raw material they had long taken for granted: ultra-high-purity (6N-grade) tungsten powder, which is almost entirely sourced from China. Following a quiet Chinese export announcement in January 2026, tungsten powder shipments to Japan dropped to zero for months. Despite frantic efforts, Japanese companies found no viable alternative; imported powder was three times more expensive and lacked the required purity. Their existing stockpiles were exhausted by mid-2026. WF6 is essential for depositing tungsten into the microscopic contact holes of High Bandwidth Memory (HBM) chips, which are crucial for advanced processors like those from Nvidia. While Japanese firms had mastered producing ultra-pure WF6 gas, their entire supply chain relied on China's 6N tungsten powder—a dependency now revealed as a fatal vulnerability. China's dominance in this "soil" results from decades of painstaking R&D by companies like Xiamen Tungsten and China Tungsten & Hightech. They overcame immense technical hurdles, such as separating chemically similar molybdenum from tungsten, to achieve mass production of the world's purest tungsten powder. With their primary suppliers gone, Kanto Denka and Central Glass announced a permanent halt to WF6 production starting July 1, 2026. This immediately created a supply crisis for major semiconductor manufacturers like Samsung and SK Hynix, forcing them to urgently seek and certify new Chinese suppliers for WF6 itself. The reversal marks a dramatic shift: China has moved from exporting low-value raw materials to controlling the high-purity foundation of a critical global tech supply chain, upending a long-established industrial hierarchy.

marsbit1 h fa

A Clod of Chinese Soil Chokes Two Japanese Giants

marsbit1 h fa

Trading

Spot
Futures
活动图片