September 22, 2026 — Cryptocurrency Security, Scams & Fraud News
The cryptocurrency world is facing another wave of security threats, and today’s biggest warning may have less to do with a traditional crypto exchange hack and more to do with artificial intelligence-powered phishing.
On September 22, 2026, Microsoft announced the disruption of EvilTokens, a cybercrime platform that used AI to help criminals compromise email accounts and conduct financial fraud. According to Microsoft, the operation was connected to more than 12,000 compromised inboxes across approximately 10,000 organizations.
The development comes as the cryptocurrency industry is already dealing with a series of recent wallet exploits, phishing campaigns, stolen digital assets, compromised infrastructure and sophisticated social-engineering attacks.
For crypto holders, traders and investors, the message is becoming increasingly clear: the next crypto scam may not look like a crypto scam at all.
Here are the biggest cryptocurrency scam, fraud, hacking and theft developments you should know about on September 22, 2026.
🚨 BREAKING: AI-Powered EvilTokens Cybercrime Platform Taken Down
One of the biggest cybersecurity stories of September 22 involves EvilTokens, a platform designed to make sophisticated phishing and financial fraud easier for criminals.
Microsoft announced today that its Digital Crimes Unit had disrupted infrastructure associated with EvilTokens following authorization from the U.S. District Court for the Eastern District of Virginia.
Microsoft described EvilTokens as a cybercrime service that incorporated AI throughout different stages of an attack, including compromising email accounts and helping criminals develop strategies for fraud and scams.
According to Microsoft’s assessment, EvilTokens had compromised more than 12,000 email inboxes belonging to approximately 10,000 organizations.
The targeted organizations reportedly included businesses and institutions in sectors such as:
- Financial services
- Construction
- Real estate
- Higher education
- Healthcare
The significance for cryptocurrency users is obvious.
Crypto companies rely heavily on email, customer-support systems, account recovery procedures and online communications. If criminals can compromise an employee’s or customer’s email account, they may be able to use that access as a stepping stone toward financial fraud.
AI Is Making Crypto Phishing More Dangerous
Traditional phishing usually involves sending a fake email or creating a fake website.
The problem in 2026 is that criminals can increasingly automate parts of the process.
Coinbase described EvilTokens as a phishing-as-a-service platform operated through Telegram bots. According to Coinbase, the service offered tools for access weaponization, email harvesting, reconnaissance and AI-powered automation.
This changes the economics of cybercrime.
A technically inexperienced criminal doesn’t necessarily need to develop an entire phishing infrastructure from scratch.
Instead, they can potentially purchase access to an existing service.
Microsoft reported that EvilTokens operated under a subscription model, with a reported $1,500 initiation fee and $500 monthly fee.
That means sophisticated cybercrime techniques can become available to a much wider group of attackers.
Why crypto users should care
Imagine receiving an email that appears to come from your exchange.
It tells you:
“We detected suspicious activity on your account.”
You click the link.
The website looks professional.
The language is convincing.
The message contains information that appears specific to you.
You log in.
And suddenly, your credentials are in the hands of an attacker.
The danger isn’t necessarily that the attacker immediately steals your crypto.
They may first steal your identity and access.
The cryptocurrency theft can come later.
⚠️ The $7.8 Million rsETH Wallet Exploit
The EvilTokens story isn’t the only major crypto security development dominating the news.
A separate series of incidents during the past week has demonstrated how complicated modern cryptocurrency attacks can become.
One of the most significant recent incidents involved approximately $7.8 million worth of rsETH being drained from an Ethereum Safe wallet.
According to reporting on the incident, the affected wallet had authorized a custom Safe module as part of its strategy-execution setup.
The attack exploited that configuration rather than compromising Safe’s core multisignature contracts or the owners’ private keys.
The incident became even more unusual because the stolen funds were reportedly intercepted by an MEV bot.
Approximately 2,882 rsETH, valued around $7.8 million at the time, was transferred to another address after the transaction was captured.
The incident demonstrates an important point:
Crypto wallets can have security risks even when the underlying blockchain remains fully operational.
The vulnerability may instead involve:
- Smart contracts
- Wallet modules
- Third-party integrations
- DeFi protocols
- Oracles
- Bridges
- Signing systems
This is why simply saying “blockchain technology is secure” does not tell the whole story.
💰 More Than $20 Million in Crypto Exploits Reported This Week
Recent incidents have affected multiple parts of the crypto ecosystem.
A September 21 report from The Crypto Times estimated that confirmed on-chain drains during the middle of September had exceeded $20 million, with incidents involving wallets, DeFi markets, bridges and other infrastructure.
Among the reported incidents were:
- The approximately $7.8 million rsETH-related Safe wallet exploit
- A Nostra oracle-related incident
- A mobile wallet incident
- A custodial wallet incident
- Bridge and signing-key compromises
The diversity of the incidents is arguably as important as the dollar value.
Attackers aren’t necessarily searching for one single vulnerability.
They’re testing the entire cryptocurrency ecosystem.
🔥 Crypto Bridges Remain a Major Target
Another major security issue involves cryptocurrency bridges.
Bridges are designed to allow assets or information to move between blockchain networks.
But they can also become attractive targets because they often involve complex smart contracts, validators, signing systems or minting mechanisms.
Recent September incidents involving Fetch.ai, NuNet and SingularityNET-related infrastructure highlighted this problem.
According to reporting, an attacker cluster drained millions of dollars worth of tokens and was subsequently associated with additional unauthorized token minting.
The same cluster was reported to hold approximately $16.77 million in tracked assets, although that figure included newly minted token inventory rather than necessarily representing realized cash proceeds.
That distinction is important.
A headline saying “attacker has $16.77 million” does not necessarily mean the attacker successfully converted $16.77 million into spendable cash.
Token prices can collapse when large unauthorized supplies are created.
Projects can also freeze addresses, revoke tokens or disable compromised bridges.
🚨 Fake Crypto Support Scams Are Still Everywhere
While sophisticated hacks receive the headlines, ordinary phishing remains one of the biggest threats to cryptocurrency users.
Scammers frequently impersonate:
- Exchange support teams
- Wallet companies
- Blockchain projects
- Token issuers
- Security departments
- Compliance teams
- Government agencies
The objective is usually to create urgency.
A victim may be told that their account has been compromised and that they must immediately:
verify → connect wallet → sign transaction → transfer funds
The entire process can happen within minutes.
Coinbase’s security guidance specifically warns users never to share their recovery phrase and recommends independently checking decentralized application URLs before interacting with them.
📧 Don’t Trust the Email Address Alone
One particularly dangerous development in modern phishing is that attackers can make messages appear extremely convincing.
Even a sender name that appears to belong to an exchange doesn’t prove anything.
Coinbase warns that scammers can create messages that appear to come from Coinbase and that users should not rely only on the displayed sender name or address.
The safest approach is simple:
Don’t click the link.
Instead, open your exchange or wallet application independently.
If there is genuinely a security issue, you should be able to find information there.
💀 The $245 Million Crypto Theft Shows How Social Engineering Works
Another major cryptocurrency crime story continues to attract attention following the guilty plea of Malone Lam.
The case involves a cryptocurrency theft of approximately $245 million.
What makes the case particularly important is that the theft wasn’t simply a story about someone breaking Bitcoin’s cryptography.
Reports have described a combination of social engineering and impersonation, demonstrating how attackers can manipulate people and gain access to cryptocurrency without needing to “hack Bitcoin.”
This distinction is critical.
Bitcoin itself doesn’t need to be hacked for someone to lose Bitcoin.
An attacker can target:
- Your email
- Your phone
- Your exchange account
- Your employees
- Your family
- Your customer-support interactions
- Your cloud accounts
- Your identity
Once an attacker controls the right access point, cryptocurrency can potentially be transferred.
🏠 Crypto Holders Are Facing a New Physical Security Threat
There is another disturbing trend affecting wealthy cryptocurrency holders: criminals increasingly have incentives to identify who owns significant amounts of digital assets.
Recent security reporting has highlighted concerns about leaked customer information being used to identify cryptocurrency holders and potentially target them offline.
The threat goes beyond a computer screen.
If criminals know:
- Who owns cryptocurrency,
- How much they potentially own,
- Where they live,
the attack surface becomes much larger.
For that reason, cryptocurrency security also involves personal privacy.
Publicly posting wallet balances, expensive purchases or detailed information about cryptocurrency holdings can create unnecessary risk.
🇬🇧 UK Authorities Continue Crackdown on Illegal Crypto Trading
The security situation isn’t limited to hackers.
Regulators are also targeting businesses believed to be operating illegally.
Earlier in September, Britain’s Financial Conduct Authority announced enforcement action against three London premises suspected of operating unregistered peer-to-peer cryptocurrency businesses.
The FCA said it worked with tax authorities and police under anti-money-laundering and counter-terrorist-financing legislation.
The regulator said unregistered peer-to-peer crypto operations could be used to move or launder illicit funds.
The development demonstrates another side of the crypto-security story:
Authorities are increasingly treating crypto infrastructure as part of the broader financial-crime ecosystem.
🧠 Why AI Could Change Cryptocurrency Scams Forever
The EvilTokens takedown may ultimately become more important than another ordinary phishing campaign.
Why?
Because AI can potentially help criminals automate tasks that previously required significant technical expertise.
For example, malicious actors can use AI-enabled systems to help with:
- Writing convincing messages
- Personalizing phishing emails
- Analyzing stolen inboxes
- Identifying valuable targets
- Generating fake websites
- Creating social-engineering scripts
- Automating reconnaissance
Microsoft’s September 22 announcement specifically described AI being used throughout the EvilTokens attack chain.
This doesn’t mean AI automatically makes every scam successful.
But it can reduce the amount of expertise and time required to conduct large-scale campaigns.
That’s potentially a major change in the economics of online fraud.
🚨 10 Red Flags of a Crypto Scam in 2026
Before sending cryptocurrency anywhere, watch for these warning signs.
1. Someone contacts you unexpectedly
Especially if they claim to represent an exchange or wallet.
2. You’re told to act immediately
Urgency is one of the oldest social-engineering techniques.
3. Someone asks for your recovery phrase
This is an enormous warning sign.
4. You’re told to move funds to a “safe wallet”
A fake support agent may claim your funds are under attack and instruct you to transfer them.
5. Someone guarantees profits
Cryptocurrency investments carry risk. Guaranteed returns should receive extreme scrutiny.
6. You must pay a fee to withdraw your own money
This is common in fake investment platforms.
7. A stranger offers an exclusive investment
Especially if they demand cryptocurrency payment.
8. You’re asked to connect your wallet to an unfamiliar website
Stop and independently investigate the application.
9. A celebrity suddenly promotes a token
Verify the information through official channels.
10. Someone asks you to keep the transaction secret
Secrecy combined with urgency is a major warning sign.
🔐 How to Protect Your Crypto Today
The most useful security strategy isn’t complicated.
It is verification.
Before approving a transaction:
Stop.
Check the website.
Check the wallet address.
Check the transaction details.
Check the permissions.
And if someone contacted you first, verify their identity through a completely separate channel.
Never rely on the contact information contained in the suspicious message.
For wallet users, Coinbase specifically recommends protecting the recovery phrase, verifying decentralized application websites and slowing down before interacting with suspicious requests.
The Biggest Crypto Security Lesson From September 22, 2026
Today’s EvilTokens takedown provides an important warning for the entire cryptocurrency industry.
The next major crypto theft might not begin with a blockchain vulnerability.
It could begin with an email.
It could begin with a phone call.
It could begin with a fake customer-support message.
It could begin with a compromised employee account.
Or it could begin with an AI-generated message that looks completely legitimate.
The cryptocurrency itself may remain perfectly secure.
The human access surrounding it may be the weak point.
Final Thoughts: Crypto Scams Are Getting Smarter
September 22, 2026 is another reminder that cryptocurrency security is evolving rapidly.
The industry is dealing with sophisticated wallet exploits, bridge compromises, phishing campaigns, social-engineering attacks and increasingly automated cybercrime.
Today’s disruption of EvilTokens is particularly significant because it demonstrates how AI can be incorporated into a criminal service designed to make phishing and financial fraud easier to conduct at scale.
Meanwhile, recent crypto exploits involving wallets and DeFi infrastructure show that technical vulnerabilities remain a serious problem.
For everyday users, the safest rule is still surprisingly simple:
Don’t trust. Verify.
Don’t share your seed phrase.
Don’t blindly click crypto links.
Don’t approve transactions you don’t understand.
Don’t believe guaranteed-return promises.
And don’t let anyone pressure you into sending cryptocurrency immediately.
In a market where a single irreversible transaction can move thousands or millions of dollars, taking an extra five minutes to verify a request could be worth far more than the opportunity you think you’re about to miss.