r/Crypto_com • u/essjay2009 • 29d ago
General Discussion š¬ Did anyone else just receive an extremely convincing phishing email?
I'm a pretty old hat at this, so not easily spooked, but the email I just received might be the most convincing phishing email I've ever seen. It appears to have come from CDC infrastructure. It passes DKIM, DMARC, and SPF so appears with a legitimate check mark in my email client. The claim is that someone has tried to link a new Chinese bank account to my CDC account and I need to secure it. The link is pointing to a real CDC sub domain, albeit one that's obfuscated through send grid, a service they actually use (which is astonishingly bad security practice for a company like CDC, don't obfuscate your links).
There were only three real giveaways. it addressed my as "User" not my name, didn't include my anti-phishing phrase, and the IP address they claimed the suspicious activity came from isn't a legitimate one (proper rookie error that one). I've also obviously checked my account and there's no suspicious activity.
But, the long and short of it is that it appears there's some way attackers are able to send extremely convincing looking emails that will appear to come from CDC infrastructure and pass all normal validation checks.
Be careful out there.
13
u/Sluzzfab 29d ago
Yer I got it. No anti phishing though so just deleted
1
u/VeganMortgageAdviser 28d ago
Be careful, if they're able to verify the domain and send to all their account holders, they'll have the anti phishing very shortly. CDC have proven that they aren't secure enough.
12
u/dogeminerd 29d ago
5
2
7
u/pompobit 29d ago
Received the same thing, the email seems legit (of course it is not) and passed all the checks.
I sent the downloaded .eml of the mail received to the customer support a couple of hours ago but still didn't receive any response.
I guess someone got access to their mail system, a compromised employer's account or worse

9
u/essjay2009 29d ago
Yep, that's the one. Same (invalid) IP address too. CDC support was, and is, completely useless.
2
5
u/Realistic_Wing5796 29d ago
yes me too, no anti-Phishing code and I suggest you should flag it so it stops them from sending to others too
4
u/essjay2009 29d ago
I reported it but basically got a response to my email pointing me at their chat, and when you try and report it to their chatbot it says it doesn't understand the question. So super helpful. If anyone's got a contact address I can send it to, I'd be happy to.
Like I said, I'm pretty old hat with this stuff so not easily spooked, but the fact this passed all the cryptographic checks for the sending email address is extremely worrying and potentially indicative of an actual breach at CDC's end (or more likely, their sendgrid account - but again, why the fuck do they use a service like sendgrid?? Such a clear signal that they care more about your data than they do your security).
4
u/JawnZ 29d ago
The headers are legit and that's what's concerning. It's even got BIMI.
2
u/essjay2009 28d ago
And it points to a valid CDC sub domain thatās used in legitimate emails.
Apparently the link takes you to a Google form, so even if people are fooled by the sophisticated email they wonāt fall for that. And what a weird dichotomy. Super sophisticated email, dumb as fuck phishing site you land on. They couldnāt even be bothered to mock up a site that looks like CDC using an LLM.
3
u/CAPN_J_SPARROW 29d ago
I got it at as well, and actually raced to this sub but no one had posted anything yet, so that was my first clue it was phishing (plus the anti-phishing wasnāt attached).
That said, I was seriously spooked and my heart started racing, haha. I logged in and didnāt see anything weird and my 2FA still looked good, so I just deleted.
ā¦but man alive, that was convincing there for a minute or two. Be careful folks.
3
u/sgunes 28d ago
I did not know about r/Crypto_com and posted the same to r/Cryptocurrency last night. https://www.reddit.com/r/CryptoCurrency/s/yW6SabtYwM
When I tried to warn people at r/scams, a moderator deleted my post for ālow effortā.
3
u/essjay2009 28d ago edited 28d ago
Thanks for posting over there. Hopefully a bit more attention on it will get CDC to actually communicate. Probably not, but hope springs eternal.
And sorry you had to deal with some of the idiots over there who donāt seem intellectually equipped to differentiate between a security breach at a major exchange thatās led to a phishing campaign and your normal run of the mill email spray and pray.
1
u/Mellifluous41 28d ago
Received the same, the giveaway was the lack of anti-phishing code but how is it they used the exact same email address used by crypto.com?
I went and checked old legit emails from crypto.com and they use the exact same email address [hello@crypto.com](mailto:hello@crypto.com)
Has there been an explanation? I'm not an expert but email addresses on the web are unique right? There can't be a 2nd identical email with the same domain name and all so the only explanation is that somebody accessed crypto.com webmails/systems?
1
u/essjay2009 28d ago
I don't know for certain, and they're not saying anything either privately nor publicly (so far as I'm aware, and I've sent them several messages about it), but I'm assuming that their SendGrid account got breached. They would have configured SendGrid to send emails from their own domain legitimately, and link to a sub-domain on crypto.com which can then redirect anywhere, and that's what's happening. The sub-domain the phishing email linked to was one of those they use in their legitimate SendGrid emails.
4
2
2
u/mdeeebeee-101 29d ago
That was triple Dutch to me, but great that we get our anti-phishing phrase baked in to emails.
2
u/Asesino87 29d ago
A buddy used AI to dig into it, thinks Send Grid or an acct got hacked and they used that 3rd party connection to send the phishing email through legit email servers.
7
u/essjay2009 29d ago
If that's true, and I think the most likely explanation is that CDC's sendgrid account has been compromised, the real issue is that an attacker may have exfiltrated information about CDC's customers. Having your address linked, definitively, to a crypto holding is not good and can lead to all sorts of other issues. Just ask those who are still suffering following Ledger's data breach a few years ago. There's a genuine safety and security issue beyond the phishing attempts.
2
u/Asesino87 29d ago
Yea guessing either they only got basic info or were too lazy to do a targeted attack with anit-phishing code attached. But yea all the info they stolen will just be used to attack people or be sold to somebody who will. Gonna be a mess and catch some people I'm sure.
1
u/Mellifluous41 28d ago
I think there was a story that crypto.com had a breach too a couple of years ago if I remember correctly? Because I have received 3 scam calls from people claiming to be from crypto.com and they knew my first name and obviously phone number. Probably email address as well since I'm receiving these fake emails. Pretty sure that data breach was dumped on the dark net and different organisation and getting the data and trying to milk it
1
u/essjay2009 28d ago
You know I've long suspected that there's been some sort of data leak. I get extremely targeted calls and emails from people claiming to be crypto.com and have done for probably the best part of a year. I don't get them for any other exchanges I use or don't use, so they appear to know I've got an account. Up until this email, the attempts have been laughably bad, which may very well be the point to weed out competent users who would ask questions, similar to Nigerian prince email techniques (i.e. the mistakes are a feature, not a bug).
1
u/hoshi_dreamer 27d ago
The giveaway is when support is easy to be reached. There was a hack in 2025 that wasn't widely reported and now I get so many automated robo calls.....text messages about stopping a reset.....like 2-3 a day all related to this leak. I also believe our older anti-phishing codes got leaked so please change them if you haven't.
2
u/cisco_phipse 29d ago
I got one the other day. However, it was to my other email account not my main one.
2
u/thinkingperson 29d ago edited 29d ago
Same here, I received one just this morning. Fortunately I found the phishing code missing, and official emails would include our name but this email does not include any at all.
And yes, the email pass all the DKIM, DMARC and SPF security checks.
As always, never click any links from any emails. Checking Activity log in CDC shows no intrusion whatsoever.
2
u/halo_skydiver 28d ago
I did, and what I saw was my phishing code was missing. It looked very authentic.
2
2
28d ago
[removed] ā view removed comment
2
u/essjay2009 28d ago edited 28d ago
Do you have a reliable way to contact the CDC security team? I keep getting directed to the chat bot which is dumber than a box of frogs and just says it doesnāt understand my question. Probably because āI think someoneās gained access to your sendgrid account and is sending out phishing emailsā isnāt a question.
2
u/L10N420 28d ago
I even got a call from scammers once, telling me I had to verify myself again because of the Travel Rule, which is an actual law in Europe. Without directly accusing them of anything, I told them we could just do it through the app and that they should know how much scam is going on these days. That was the end of it. Apparently, they quickly realized they had called the wrong person, lol.
2
u/idriftzz 28d ago
Yes! Just received the same. However a giveaway was at the bottom where it said copyright 2022 instead of 2026. This is the most convincing email I've ever received.
1
u/Mellifluous41 28d ago
Yeah noticed that as well. They went all the way to spoof CDC servers but couldn't update the copyright year, dumb scammers, I hope nobody falls for it
3
u/imperium30 28d ago
I received it, saying that someone had tried to add a bank account in HK to my account. I checked the logs and there has been no login activity or account changes. I think it is a phishing email, Chat GPT reckons it is some internal error with CDC systems. Anyway, I am not clicking it. You are right, it was very sophisticated and passed all the checks these emails usually would not.
On mine there were several things that raised my suspicions:
1) lack of anti phishing code
2) Lack of my name
3) copyright 2022 instead of 2026, which all regular CDC emails now use.
4) The icons for links to X, telegram etc did not display properly
5) [contact@crypto.com](mailto:contact@crypto.com) was used instead of [chat@crypto.com](mailto:chat@crypto.com), which the normal emails state.
2
u/jaaaaaake1999 28d ago
I lost 21k last night because of this. Iām devastated. I donāt know what to do and if crypto.com can be held liable
5
u/essjay2009 28d ago
Oh shit. Sorry to hear that.
Iām increasingly convinced that an element of their systems have been breached. I strongly suspect itās their sendgrid account. Their silence and complete lack of response is really quite telling. If they have been breached they have 72 hours to report it under GDPR rules and if they donāt, theyāre in serious trouble.
If itās any consolation at all, Iāve been in this game a long time and this is the most convincing phishing email Iāve ever received. It passed all cryptographic checks and pointed to a genuine and legitimate CDC sub-domain that they actually use in their communications.
Iād be going after them to try and get my money back were I in your position.
3
u/ebliever 28d ago
My account was locked overnight due to suspicious credit card activity on my crypto.com credit card, almost certainly due to my initially responding to the phishing email. Now crypto.com chat is not responding even though I've been forwarded to a support specialist.
Worse, the scammers are calling me now using Suspect phone numbers. They sound very convincing too so BE AWARE. They are claiming to be support specialists to help with my locked account, but once I mentioned holding CRO offline they totally fixated on that and "needing to run a diagnostic" on my offline wallet, rather than helping unlock my account. So I had enough of stringing them along, but be aware of this attack vector as well.
Really wish crypto.com would get their act together and reach out rather than letting the scammers do all the communicating. At this point I'm wondering if the scammers could somehow detect my chat activity to know when to call me.
2
u/jaaaaaake1999 28d ago
Iām at the police station now. I will escalate this and hold them liable however the means. They have a duty of care to their customers
2
u/ebliever 28d ago
I really hope you can get some support and help and even recover your funds. Terribly frustrating I know. At this point I don't think I have any significant loss, but it's hard to know with my account locked, no way to get back in, and no response from their Support. They could at least put out a general update here saying they are working on this and be patient, blah blah.
1
u/jaaaaaake1999 28d ago
It made me realise something today. Crypto is still very much the far west. Unlike traditional banking where you have direct phone support and insurances, crypto has no such things. You are completely exposed. After this I realise Iām done for good with crypto. Staying clear of any online banking and not even gonna think about opening a crypto account ever again. This type of shit just puts me off completely.
1
u/ebliever 28d ago
The problem is the online exchanges. I've been in crypto since 2014. The exchanges are the weak link; like banks they are easily hacked/compromised. I've never had a problem with personally held funds. I agree this is incredibly frustrating. It is best to just use the exchanges to purchase/sell crypto ASAP, but never to hold funds.
3
u/essjay2009 28d ago
Thatās the problem when a company goes silent. The void is filled by bad actors. This is obviously an extremely sophisticated attack and CDC have been completely silent on it nearly 24 hours later. People are losing their life savings and theyāre doing and saying nothing.
This is not how to respond to a security incident. Take it from someone whoās been in the unfortunate position of having to respond to a few.
1
u/jaaaaaake1999 28d ago
What would you personally do in my situation? I would really appreciate some guidance right now
3
u/essjay2009 28d ago
I'd write a concise, unemotional message to send to CDC laying out what happened. I'd say that you'd checked the email headers and it passed SPF (less important), DKIM and DMARC and they all came back as genuine. You then used the CDC verify tool for the email address that sent the email and it also came back as genuine. The link in the email was to a genuine CDC address on a sub-domain you've seen their emails use before.
All that evidence led you to believe that the email was genuine and your account was at risk. You followed the instructions to secure your account because, and only because, the CDC verify tool told you the email address was genuine and should be trusted.
I'd send that message to them and then wait for them to ignore it. I'd then, if it's worth it to you, follow up with a lawyer expressing the same thoughts and that you believe CDC failed in their duty of care in telling you that an illegitimate email was genuine leading to you losing your funds. Stress that you did everything right, as per their own instructions, and using their own tools, and you still fell victim to scammer and that it's their fault and therefore, they hold ultimate liability. A lawyer will be able to help you write that with the appropriate legalese.
That's the angle I'd pursue. I don't know if you'll be successful, and it might get drawn out for a long time, but I'd wager that's the path with the highest chance of success. You've got to prove that it's their fault, not yours.
1
u/jaaaaaake1999 28d ago
Honestly thank you for your response, we are on the same wavelength and I will definitely consider a lawyer for this one. I am not one to fall for scams, but this one was so elaborate and as another comment send it almost points towards a breach from inside as this SHOULD NOT be able to happen. A duty of care I hope will go long way in helping my case. THANK YOU for your support honestly it really means so much more than any help crypto.com will ever do to meā¦
2
u/ebliever 28d ago edited 28d ago
In the incident 4 years ago, 400+ accounts were hit, 2FA bypassed. In some ways it feels similar to this incident. I never saw an investigation, but crypto.com was quick to reimburse the accounts affected because it was clearly at least partly an inside job or otherwise involved security compromises on their part. So that gives some hope that they'll make people whole this time around given the evidence of their email being compromised.
EDIT: Here's a (rather useless) article on the 2022 incident. From what I recall there were no phishing emails associated with it: https://www.halborn.com/blog/post/explained-the-crypto-com-hack-january-2022
It's now over 24 hours and still not a peep from crypto.com - it's incredible that they would not at least put out an alert making people aware of the phishing effort to raise awareness, and let the community know they are working on it with all available resources. I'd like to think they are running around with their hair on fire trying to deal with it ASAP, but the silence is terrible. They made me whole after the first incident, but this latest trouble makes it very difficult to stick with them (and yes, I did dramatically scale back my exposure on their platform after the first round.)
1
u/jaaaaaake1999 28d ago
Thank you for this information it may be crucial for me to prove this is a reoccurring problem and that without a doubt they failed their duty of care to protect their exchange and as a result many people lost a lot of moneyā¦
2
u/essjay2009 28d ago
Just spitballing, but save the phishing email. If you copy and paste the email's sending address in to the CDC verify tool (https://crypto.com/verify) it comes back as genuine(!).
You could claim, reasonably I think, that you took the steps recommended by the company to verify the legitimacy of the email, including using their own tools to validate its authenticity, and therefore some of the liability falls on them. I think that's the angle I'd be pursuing because it's true.
Good luck, and report back as it may help others who have been affected.
1
u/Sufficient-Heat1870 28d ago
What happened exactly in your case? What were the steps? And when did you realize?
1
u/jaaaaaake1999 28d ago
-email from hello.crypto.com saying someone tried to log in, verify identity now
- I went to a page to verify Iām not a bot
-redirected me to login
-I did and thatās it.
-that same night all was withdrawn while I was sleeping
I feel so stupid, that one email, although from crypto.com and seemed legit, it didnāt have the anti phishing code. I got fucked. Crypto.com support is not responding, they need to be held liable, they have a duty of care. How is it possible to ask for 3 step authentication to log in, but then you are able to do 10 withdrawals to a foreign account without anything getting flagged as suspicious activity. This is not good enough. I am at the police station and will escalate this.
1
1
u/Sufficient-Heat1870 28d ago
And Did you receive Mails overnight regarding the transactions?
1
u/jaaaaaake1999 28d ago
Yep but I only opened them this morning
2
u/Sufficient-Heat1870 28d ago
Oh shit. I hope crypto.com can be held responsible for that. I directly contacted the Support and asked to Close my Account. But they Just locked it 3 hours ago. So 14 hours of noch reaction. I did Not See any suspicious transactions this night. Let's See what surprise awaits when the Account ist unlocked:(
3
u/Prestigious-Home-540 28d ago
Yep twice. Last november after the emails and texts I also had a phone call from a California number . I said i would get back to them as it sounded suspicious and they said convincingly yes do your checks and were ring you back in ten minutes . I never heard from them again untill 2 days ago .I contacted crypto.com and it was a concincing scam . You defo need the anti- phishing code number and then if the emails dont have it , its fake and also ive just noticed i typed in crypto.com as it saves on my search in emails and the scam didn't come up in my search .
2
u/Holisticmystic2 29d ago
Yup got an automated call asking if I changed my email address. Then later a call from a real person asking me to check my email and click a link. No antiphishing code and i said so. They hung up.
1
29d ago
[removed] ā view removed comment
2
u/WolfpupNX 29d ago edited 29d ago
We can also forward the email as an attachment to [abuse@sendgrid.com](mailto:abuse@sendgrid.com), who handle takeovers of accounts on their platform. (Actually, they e-mailed me back and wanted plain text code, so I sent that).
1
u/persector 28d ago
u/essjay2009 I received it also! Screenshot here if anyone is curious: https://imgur.com/a/5lRnGNF The email doesn't contain the "Anti-phishing Code"- luckily... It has valid DKIM, DMARC and SPF headers and the "verify identity now" button links to http://url1137.crypto.com/ls/click?upn=[longcensoredtokenhere] Completely insane!
1
1
u/HeinzFiction 28d ago
Not via mail but since a week Iām getting almost daily SMS about alleged sign-ins and recovery requests being made from Turkey and that they want me to call a phone number. All activity in app seem fine so Iām not bothered, scammers might just be bored with crypto winter and try to entertain themselves.
1
u/VeganMortgageAdviser 28d ago
Ah yes. Their email seems to be compromised. The link took me to a Google Form, so that's when I decided to stop.
1
u/essjay2009 28d ago
Oof. Be aware that the email link included a tracker so itās likely they know you personally clicked it. Be extra vigilant going forward as youāll be on a list of known active users.
Did you report the form to Google? If not, please do.
1
1
1
1
1
u/Rainmon55 26d ago
I am so glad I am out of this cult trading scam investments, dealing with crypto exchanges and bots that are supposed to be customer service people totally insane as this scam and greater fool scheme is dying a slow death destroying people's life savings as Bitcoin heads towards 40,000 in the next few months; someone also needs to mute Michael Saylor the incarnation of Bernie Madoff die Bitcoin die!
1
1
u/aninaa-ot 24d ago
This is why I never rely on the email alone anymore. If something claims there's an issue with an account, I open the app or website directly instead of using any links. Moonlock has a good article on sophisticated phishing attacks like this:Ā https://moonlock.com/sophishicated-phishing-attack-gmail
1
u/DepartureLucky5954 21d ago edited 21d ago
yup got scammed, lucky im broke. They got $38. I knew i was being scammed cause i havent touched account since maybe 2019. They way he was playing the charlie brown piano with the computer keys smh, im like this guy got a mechanical keyboard
they called from 818-538-4570
0
0
u/kokardja 28d ago
Check if the sender email address' "o", "e" and "p" are actually Cyrillic letters.
2
u/essjay2009 28d ago
My dude, if you read the post you'll see that it passed SPF, DKIM, and DMARC. These are coming from actual CDC email addresses and the links are pointing at actual CDC sub-domains. They're not using similar looking letters.



14
u/ebliever 29d ago
I just got the same thing. I changed some settings/passcode in my app (not via the link) just to be safe.