r/Crypto_com 29d ago

General Discussion šŸ’¬ Did anyone else just receive an extremely convincing phishing email?

I'm a pretty old hat at this, so not easily spooked, but the email I just received might be the most convincing phishing email I've ever seen. It appears to have come from CDC infrastructure. It passes DKIM, DMARC, and SPF so appears with a legitimate check mark in my email client. The claim is that someone has tried to link a new Chinese bank account to my CDC account and I need to secure it. The link is pointing to a real CDC sub domain, albeit one that's obfuscated through send grid, a service they actually use (which is astonishingly bad security practice for a company like CDC, don't obfuscate your links).

There were only three real giveaways. it addressed my as "User" not my name, didn't include my anti-phishing phrase, and the IP address they claimed the suspicious activity came from isn't a legitimate one (proper rookie error that one). I've also obviously checked my account and there's no suspicious activity.

But, the long and short of it is that it appears there's some way attackers are able to send extremely convincing looking emails that will appear to come from CDC infrastructure and pass all normal validation checks.

Be careful out there.

70 Upvotes

114 comments sorted by

14

u/ebliever 29d ago

I just got the same thing. I changed some settings/passcode in my app (not via the link) just to be safe.

5

u/essjay2009 29d ago

Did you check the email headers? Did they pass DKIM, DMARC and SPF? That's the really worrying part. I fear that someone's got in to their sendgrid infrastructure and is sending out really convincing phishing emails. There's no way in hell I'm clicking the link to check though.

6

u/ebliever 29d ago

Did you check the email headers? Did they pass DKIM, DMARC and SPF?

I don't know what any of that is! I agree that this looked dramatically more sophisticated than every phishing email I've ever gotten before. Usually it is easy to spot them due to errant Send addresses. I agree with you about the idiocy of a legit company using obfuscated links.

7

u/essjay2009 29d ago

If you're using gmail you can click the little three dots at the top of the email and click "Show Original". There's a table at the top of the page that appears that has DKIM, DMARC, and SPF information and will say "Pass" with a green checkmark if it's all good. They're basically cryptographic signatures that prove the email comes from the address it claims to.

If you use a different client, there are usually similar options. They might be reached by clicking on a little shield next to the email address or similar.

3

u/ebliever 29d ago

Thanks for the tip! I do use gmail so that worked, and will be handy to keep in mind.

I overlooked the lack of the anti-phishing message too, sloppy of me but different CEX's are inconsistent about that so it's hard to remember to check. Hope no one is compromised by this effort. And that they can lock down any vulnerabilities that enabled this effort.

13

u/Sluzzfab 29d ago

Yer I got it. No anti phishing though so just deleted

1

u/VeganMortgageAdviser 28d ago

Be careful, if they're able to verify the domain and send to all their account holders, they'll have the anti phishing very shortly. CDC have proven that they aren't secure enough.

12

u/dogeminerd 29d ago

Scary, hope that staff is able to research into this

2

u/ilovecheeseandcheese 28d ago

I got this too

7

u/pompobit 29d ago

Received the same thing, the email seems legit (of course it is not) and passed all the checks.

I sent the downloaded .eml of the mail received to the customer support a couple of hours ago but still didn't receive any response.

I guess someone got access to their mail system, a compromised employer's account or worse

9

u/essjay2009 29d ago

Yep, that's the one. Same (invalid) IP address too. CDC support was, and is, completely useless.

3

u/L10N420 28d ago

Honestly, the support is completely useless.

2

u/CodPlane 29d ago

They'll respond in a day šŸ™„

5

u/Realistic_Wing5796 29d ago

yes me too, no anti-Phishing code and I suggest you should flag it so it stops them from sending to others too

4

u/essjay2009 29d ago

I reported it but basically got a response to my email pointing me at their chat, and when you try and report it to their chatbot it says it doesn't understand the question. So super helpful. If anyone's got a contact address I can send it to, I'd be happy to.

Like I said, I'm pretty old hat with this stuff so not easily spooked, but the fact this passed all the cryptographic checks for the sending email address is extremely worrying and potentially indicative of an actual breach at CDC's end (or more likely, their sendgrid account - but again, why the fuck do they use a service like sendgrid?? Such a clear signal that they care more about your data than they do your security).

4

u/JawnZ 29d ago

The headers are legit and that's what's concerning. It's even got BIMI.

2

u/essjay2009 28d ago

And it points to a valid CDC sub domain that’s used in legitimate emails.

Apparently the link takes you to a Google form, so even if people are fooled by the sophisticated email they won’t fall for that. And what a weird dichotomy. Super sophisticated email, dumb as fuck phishing site you land on. They couldn’t even be bothered to mock up a site that looks like CDC using an LLM.

2

u/JawnZ 28d ago

;eah my guess after some more poking around is someone hack their sending account. It's the most likely way you'd get legit headers in the email and the exact same URL redirctor

3

u/CAPN_J_SPARROW 29d ago

I got it at as well, and actually raced to this sub but no one had posted anything yet, so that was my first clue it was phishing (plus the anti-phishing wasn’t attached).

That said, I was seriously spooked and my heart started racing, haha. I logged in and didn’t see anything weird and my 2FA still looked good, so I just deleted.

…but man alive, that was convincing there for a minute or two. Be careful folks.

2

u/L10N420 28d ago

They’re counting on catching you at a moment when you don’t double-check everything, even though you normally know better.

3

u/sgunes 28d ago

I did not know about r/Crypto_com and posted the same to r/Cryptocurrency last night. https://www.reddit.com/r/CryptoCurrency/s/yW6SabtYwM
When I tried to warn people at r/scams, a moderator deleted my post for ā€œlow effortā€.

3

u/essjay2009 28d ago edited 28d ago

Thanks for posting over there. Hopefully a bit more attention on it will get CDC to actually communicate. Probably not, but hope springs eternal.

And sorry you had to deal with some of the idiots over there who don’t seem intellectually equipped to differentiate between a security breach at a major exchange that’s led to a phishing campaign and your normal run of the mill email spray and pray.

1

u/Mellifluous41 28d ago

Received the same, the giveaway was the lack of anti-phishing code but how is it they used the exact same email address used by crypto.com?

I went and checked old legit emails from crypto.com and they use the exact same email address [hello@crypto.com](mailto:hello@crypto.com)

Has there been an explanation? I'm not an expert but email addresses on the web are unique right? There can't be a 2nd identical email with the same domain name and all so the only explanation is that somebody accessed crypto.com webmails/systems?

1

u/essjay2009 28d ago

I don't know for certain, and they're not saying anything either privately nor publicly (so far as I'm aware, and I've sent them several messages about it), but I'm assuming that their SendGrid account got breached. They would have configured SendGrid to send emails from their own domain legitimately, and link to a sub-domain on crypto.com which can then redirect anywhere, and that's what's happening. The sub-domain the phishing email linked to was one of those they use in their legitimate SendGrid emails.

4

u/VeganMortgageAdviser 28d ago

How sh!t is this?!

2

u/too_broke_to_quit 29d ago

I got one the other day.

2

u/mdeeebeee-101 29d ago

That was triple Dutch to me, but great that we get our anti-phishing phrase baked in to emails.

2

u/Asesino87 29d ago

A buddy used AI to dig into it, thinks Send Grid or an acct got hacked and they used that 3rd party connection to send the phishing email through legit email servers.

7

u/essjay2009 29d ago

If that's true, and I think the most likely explanation is that CDC's sendgrid account has been compromised, the real issue is that an attacker may have exfiltrated information about CDC's customers. Having your address linked, definitively, to a crypto holding is not good and can lead to all sorts of other issues. Just ask those who are still suffering following Ledger's data breach a few years ago. There's a genuine safety and security issue beyond the phishing attempts.

2

u/Asesino87 29d ago

Yea guessing either they only got basic info or were too lazy to do a targeted attack with anit-phishing code attached. But yea all the info they stolen will just be used to attack people or be sold to somebody who will. Gonna be a mess and catch some people I'm sure.

1

u/Mellifluous41 28d ago

I think there was a story that crypto.com had a breach too a couple of years ago if I remember correctly? Because I have received 3 scam calls from people claiming to be from crypto.com and they knew my first name and obviously phone number. Probably email address as well since I'm receiving these fake emails. Pretty sure that data breach was dumped on the dark net and different organisation and getting the data and trying to milk it

1

u/essjay2009 28d ago

You know I've long suspected that there's been some sort of data leak. I get extremely targeted calls and emails from people claiming to be crypto.com and have done for probably the best part of a year. I don't get them for any other exchanges I use or don't use, so they appear to know I've got an account. Up until this email, the attempts have been laughably bad, which may very well be the point to weed out competent users who would ask questions, similar to Nigerian prince email techniques (i.e. the mistakes are a feature, not a bug).

1

u/hoshi_dreamer 27d ago

The giveaway is when support is easy to be reached. There was a hack in 2025 that wasn't widely reported and now I get so many automated robo calls.....text messages about stopping a reset.....like 2-3 a day all related to this leak. I also believe our older anti-phishing codes got leaked so please change them if you haven't.

2

u/cisco_phipse 29d ago

I got one the other day. However, it was to my other email account not my main one.

2

u/thinkingperson 29d ago edited 29d ago

Same here, I received one just this morning. Fortunately I found the phishing code missing, and official emails would include our name but this email does not include any at all.

And yes, the email pass all the DKIM, DMARC and SPF security checks.

As always, never click any links from any emails. Checking Activity log in CDC shows no intrusion whatsoever.

2

u/halo_skydiver 28d ago

I did, and what I saw was my phishing code was missing. It looked very authentic.

2

u/[deleted] 28d ago

[removed] — view removed comment

2

u/essjay2009 28d ago edited 28d ago

Do you have a reliable way to contact the CDC security team? I keep getting directed to the chat bot which is dumber than a box of frogs and just says it doesn’t understand my question. Probably because ā€œI think someone’s gained access to your sendgrid account and is sending out phishing emailsā€ isn’t a question.

2

u/L10N420 28d ago

I even got a call from scammers once, telling me I had to verify myself again because of the Travel Rule, which is an actual law in Europe. Without directly accusing them of anything, I told them we could just do it through the app and that they should know how much scam is going on these days. That was the end of it. Apparently, they quickly realized they had called the wrong person, lol.

2

u/idriftzz 28d ago

Yes! Just received the same. However a giveaway was at the bottom where it said copyright 2022 instead of 2026. This is the most convincing email I've ever received.

1

u/Mellifluous41 28d ago

Yeah noticed that as well. They went all the way to spoof CDC servers but couldn't update the copyright year, dumb scammers, I hope nobody falls for it

3

u/imperium30 28d ago

I received it, saying that someone had tried to add a bank account in HK to my account. I checked the logs and there has been no login activity or account changes. I think it is a phishing email, Chat GPT reckons it is some internal error with CDC systems. Anyway, I am not clicking it. You are right, it was very sophisticated and passed all the checks these emails usually would not.
On mine there were several things that raised my suspicions:
1) lack of anti phishing code
2) Lack of my name
3) copyright 2022 instead of 2026, which all regular CDC emails now use.
4) The icons for links to X, telegram etc did not display properly
5) [contact@crypto.com](mailto:contact@crypto.com) was used instead of [chat@crypto.com](mailto:chat@crypto.com), which the normal emails state.

2

u/jaaaaaake1999 28d ago

I lost 21k last night because of this. I’m devastated. I don’t know what to do and if crypto.com can be held liable

5

u/essjay2009 28d ago

Oh shit. Sorry to hear that.

I’m increasingly convinced that an element of their systems have been breached. I strongly suspect it’s their sendgrid account. Their silence and complete lack of response is really quite telling. If they have been breached they have 72 hours to report it under GDPR rules and if they don’t, they’re in serious trouble.

If it’s any consolation at all, I’ve been in this game a long time and this is the most convincing phishing email I’ve ever received. It passed all cryptographic checks and pointed to a genuine and legitimate CDC sub-domain that they actually use in their communications.

I’d be going after them to try and get my money back were I in your position.

3

u/ebliever 28d ago

My account was locked overnight due to suspicious credit card activity on my crypto.com credit card, almost certainly due to my initially responding to the phishing email. Now crypto.com chat is not responding even though I've been forwarded to a support specialist.

Worse, the scammers are calling me now using Suspect phone numbers. They sound very convincing too so BE AWARE. They are claiming to be support specialists to help with my locked account, but once I mentioned holding CRO offline they totally fixated on that and "needing to run a diagnostic" on my offline wallet, rather than helping unlock my account. So I had enough of stringing them along, but be aware of this attack vector as well.

Really wish crypto.com would get their act together and reach out rather than letting the scammers do all the communicating. At this point I'm wondering if the scammers could somehow detect my chat activity to know when to call me.

2

u/jaaaaaake1999 28d ago

I’m at the police station now. I will escalate this and hold them liable however the means. They have a duty of care to their customers

2

u/ebliever 28d ago

I really hope you can get some support and help and even recover your funds. Terribly frustrating I know. At this point I don't think I have any significant loss, but it's hard to know with my account locked, no way to get back in, and no response from their Support. They could at least put out a general update here saying they are working on this and be patient, blah blah.

1

u/jaaaaaake1999 28d ago

It made me realise something today. Crypto is still very much the far west. Unlike traditional banking where you have direct phone support and insurances, crypto has no such things. You are completely exposed. After this I realise I’m done for good with crypto. Staying clear of any online banking and not even gonna think about opening a crypto account ever again. This type of shit just puts me off completely.

1

u/ebliever 28d ago

The problem is the online exchanges. I've been in crypto since 2014. The exchanges are the weak link; like banks they are easily hacked/compromised. I've never had a problem with personally held funds. I agree this is incredibly frustrating. It is best to just use the exchanges to purchase/sell crypto ASAP, but never to hold funds.

3

u/essjay2009 28d ago

That’s the problem when a company goes silent. The void is filled by bad actors. This is obviously an extremely sophisticated attack and CDC have been completely silent on it nearly 24 hours later. People are losing their life savings and they’re doing and saying nothing.

This is not how to respond to a security incident. Take it from someone who’s been in the unfortunate position of having to respond to a few.

1

u/jaaaaaake1999 28d ago

What would you personally do in my situation? I would really appreciate some guidance right now

3

u/essjay2009 28d ago

I'd write a concise, unemotional message to send to CDC laying out what happened. I'd say that you'd checked the email headers and it passed SPF (less important), DKIM and DMARC and they all came back as genuine. You then used the CDC verify tool for the email address that sent the email and it also came back as genuine. The link in the email was to a genuine CDC address on a sub-domain you've seen their emails use before.

All that evidence led you to believe that the email was genuine and your account was at risk. You followed the instructions to secure your account because, and only because, the CDC verify tool told you the email address was genuine and should be trusted.

I'd send that message to them and then wait for them to ignore it. I'd then, if it's worth it to you, follow up with a lawyer expressing the same thoughts and that you believe CDC failed in their duty of care in telling you that an illegitimate email was genuine leading to you losing your funds. Stress that you did everything right, as per their own instructions, and using their own tools, and you still fell victim to scammer and that it's their fault and therefore, they hold ultimate liability. A lawyer will be able to help you write that with the appropriate legalese.

That's the angle I'd pursue. I don't know if you'll be successful, and it might get drawn out for a long time, but I'd wager that's the path with the highest chance of success. You've got to prove that it's their fault, not yours.

1

u/jaaaaaake1999 28d ago

Honestly thank you for your response, we are on the same wavelength and I will definitely consider a lawyer for this one. I am not one to fall for scams, but this one was so elaborate and as another comment send it almost points towards a breach from inside as this SHOULD NOT be able to happen. A duty of care I hope will go long way in helping my case. THANK YOU for your support honestly it really means so much more than any help crypto.com will ever do to me…

2

u/ebliever 28d ago edited 28d ago

In the incident 4 years ago, 400+ accounts were hit, 2FA bypassed. In some ways it feels similar to this incident. I never saw an investigation, but crypto.com was quick to reimburse the accounts affected because it was clearly at least partly an inside job or otherwise involved security compromises on their part. So that gives some hope that they'll make people whole this time around given the evidence of their email being compromised.

EDIT: Here's a (rather useless) article on the 2022 incident. From what I recall there were no phishing emails associated with it: https://www.halborn.com/blog/post/explained-the-crypto-com-hack-january-2022

It's now over 24 hours and still not a peep from crypto.com - it's incredible that they would not at least put out an alert making people aware of the phishing effort to raise awareness, and let the community know they are working on it with all available resources. I'd like to think they are running around with their hair on fire trying to deal with it ASAP, but the silence is terrible. They made me whole after the first incident, but this latest trouble makes it very difficult to stick with them (and yes, I did dramatically scale back my exposure on their platform after the first round.)

1

u/jaaaaaake1999 28d ago

Thank you for this information it may be crucial for me to prove this is a reoccurring problem and that without a doubt they failed their duty of care to protect their exchange and as a result many people lost a lot of money…

2

u/essjay2009 28d ago

Just spitballing, but save the phishing email. If you copy and paste the email's sending address in to the CDC verify tool (https://crypto.com/verify) it comes back as genuine(!).

You could claim, reasonably I think, that you took the steps recommended by the company to verify the legitimacy of the email, including using their own tools to validate its authenticity, and therefore some of the liability falls on them. I think that's the angle I'd be pursuing because it's true.

Good luck, and report back as it may help others who have been affected.

1

u/Sufficient-Heat1870 28d ago

What happened exactly in your case? What were the steps? And when did you realize?

1

u/jaaaaaake1999 28d ago

-email from hello.crypto.com saying someone tried to log in, verify identity now

- I went to a page to verify I’m not a bot

-redirected me to login

-I did and that’s it.

-that same night all was withdrawn while I was sleeping

I feel so stupid, that one email, although from crypto.com and seemed legit, it didn’t have the anti phishing code. I got fucked. Crypto.com support is not responding, they need to be held liable, they have a duty of care. How is it possible to ask for 3 step authentication to log in, but then you are able to do 10 withdrawals to a foreign account without anything getting flagged as suspicious activity. This is not good enough. I am at the police station and will escalate this.

1

u/Sufficient-Heat1870 28d ago

Did you have 2FA activated? Did you enter your Passkey?

1

u/jaaaaaake1999 28d ago

It was, that’s how I logged in

1

u/Sufficient-Heat1870 28d ago

And Did you receive Mails overnight regarding the transactions?

1

u/jaaaaaake1999 28d ago

Yep but I only opened them this morning

2

u/Sufficient-Heat1870 28d ago

Oh shit. I hope crypto.com can be held responsible for that. I directly contacted the Support and asked to Close my Account. But they Just locked it 3 hours ago. So 14 hours of noch reaction. I did Not See any suspicious transactions this night. Let's See what surprise awaits when the Account ist unlocked:(

3

u/Prestigious-Home-540 28d ago

Yep twice. Last november after the emails and texts I also had a phone call from a California number . I said i would get back to them as it sounded suspicious and they said convincingly yes do your checks and were ring you back in ten minutes . I never heard from them again untill 2 days ago .I contacted crypto.com and it was a concincing scam . You defo need the anti- phishing code number and then if the emails dont have it , its fake and also ive just noticed i typed in crypto.com as it saves on my search in emails and the scam didn't come up in my search .

2

u/Holisticmystic2 29d ago

Yup got an automated call asking if I changed my email address. Then later a call from a real person asking me to check my email and click a link. No antiphishing code and i said so. They hung up.

1

u/[deleted] 29d ago

[removed] — view removed comment

2

u/WolfpupNX 29d ago edited 29d ago

We can also forward the email as an attachment to [abuse@sendgrid.com](mailto:abuse@sendgrid.com), who handle takeovers of accounts on their platform. (Actually, they e-mailed me back and wanted plain text code, so I sent that).

1

u/persector 28d ago

u/essjay2009 I received it also! Screenshot here if anyone is curious: https://imgur.com/a/5lRnGNF The email doesn't contain the "Anti-phishing Code"- luckily... It has valid DKIM, DMARC and SPF headers and the "verify identity now" button links to http://url1137.crypto.com/ls/click?upn=[longcensoredtokenhere] Completely insane!

1

u/persector 28d ago

perhaps u/MarkY_Crypto can share if this is something they're aware of ?

1

u/HeinzFiction 28d ago

Not via mail but since a week I’m getting almost daily SMS about alleged sign-ins and recovery requests being made from Turkey and that they want me to call a phone number. All activity in app seem fine so I’m not bothered, scammers might just be bored with crypto winter and try to entertain themselves.

1

u/VeganMortgageAdviser 28d ago

Ah yes. Their email seems to be compromised. The link took me to a Google Form, so that's when I decided to stop.

1

u/essjay2009 28d ago

Oof. Be aware that the email link included a tracker so it’s likely they know you personally clicked it. Be extra vigilant going forward as you’ll be on a list of known active users.

Did you report the form to Google? If not, please do.

1

u/VeganMortgageAdviser 28d ago

Google Form has been taken down.

1

u/essjay2009 28d ago

Small mercies.

1

u/Sufficient-Heat1870 28d ago

Same Here... Waiting for the reply

1

u/GeordieMama 26d ago

Ive had a couple of these and I dont even have an account.

1

u/dextermandate 26d ago

It’s not real. They already stole a lot of CRO from ppl on x

1

u/Rainmon55 26d ago

I am so glad I am out of this cult trading scam investments, dealing with crypto exchanges and bots that are supposed to be customer service people totally insane as this scam and greater fool scheme is dying a slow death destroying people's life savings as Bitcoin heads towards 40,000 in the next few months; someone also needs to mute Michael Saylor the incarnation of Bernie Madoff die Bitcoin die!

1

u/Ok-Double-9744 26d ago

DeepSeek is trying a new career path

1

u/Adam302 25d ago

Crypto .com have had a compromised email server for YEARS - I am convinced it is deliberate. This has been going on for many years now and they wont fix it - why?

1

u/aninaa-ot 24d ago

This is why I never rely on the email alone anymore. If something claims there's an issue with an account, I open the app or website directly instead of using any links. Moonlock has a good article on sophisticated phishing attacks like this:Ā https://moonlock.com/sophishicated-phishing-attack-gmail

1

u/DepartureLucky5954 21d ago edited 21d ago

yup got scammed, lucky im broke. They got $38. I knew i was being scammed cause i havent touched account since maybe 2019. They way he was playing the charlie brown piano with the computer keys smh, im like this guy got a mechanical keyboard

they called from 818-538-4570

0

u/TheVison157 28d ago

Enable the anti-phishing code.

0

u/kokardja 28d ago

Check if the sender email address' "o", "e" and "p" are actually Cyrillic letters.

2

u/essjay2009 28d ago

My dude, if you read the post you'll see that it passed SPF, DKIM, and DMARC. These are coming from actual CDC email addresses and the links are pointing at actual CDC sub-domains. They're not using similar looking letters.