Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14
Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16
Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17
Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14
Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16
Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17
Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
Deprecated: Creation of dynamic property CSF_Field_color::$field is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14
Deprecated: Creation of dynamic property CSF_Field_color::$value is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 15
Deprecated: Creation of dynamic property CSF_Field_color::$unique is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16
Deprecated: Creation of dynamic property CSF_Field_color::$where is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17
Deprecated: Creation of dynamic property CSF_Field_color::$parent is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14
Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16
Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17
Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14
Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16
Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17
Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
Deprecated: Creation of dynamic property CSF_Field_color::$field is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14
Deprecated: Creation of dynamic property CSF_Field_color::$value is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 15
Deprecated: Creation of dynamic property CSF_Field_color::$unique is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16
Deprecated: Creation of dynamic property CSF_Field_color::$where is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17
Deprecated: Creation of dynamic property CSF_Field_color::$parent is deprecated in /home/u873351629/domains/coinradar.live/public_html/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
A large-scale phishing campaign dubbed ‘PoisonSeed’ compromises corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets.
According to SilentPush, the campaign targets Coinbase and Ledger using compromised accounts at Mailchimp, SendGrid, HubSpot, Mailgun, and Zoho.
The researchers link the campaign to recent incidents, such as the case of Troy Hunt’s Mailchimp account compromise from late last month and an Akamai SendGrid account hack BleepingComputer reported in mid-March 2025, where the legitimate account was used to send out Coinbase seed phrase phishing emails.
Although the PoisonSeed campaign shares similarities with operations by the CryptoChameleon and Scattered Spider threat actors, Silent Push categorizes it separately due to code differences and other differentiating factors.
PoisonSeed attack chain
The first step in the attack is to identify high-value targets with access to CRM and bulk email platforms. This can be done by checking what email companies use for their newsletters or marketing and finding employees in related positions.
Next, they target them with professionally crafted phishing emails sent from spoofed addresses, taking them to fake login pages hosted on carefully named domains to appear legitimate.
For example, in emails targeting MailChimp customers, the threat actors used the domains mail-chimpservices[.]com, mailchimp-sso[.]com, and mailchimp-ssologin[.]com.
Once their credentials are stolen, the attackers export mailing lists and generate new API keys to maintain access to the hijacked account even if the victim quickly changes their password.
The attacker then uses the compromised account to send crypto-themed phishing spam to the extracted mailing lists with alerts that prompt the recipient’s action, like ‘Coinbase is transitioning to self-custodial wallets.’
The phishing email includes a Coinbase wallet seed phrase, telling the user to enter it into a new crypto wallet as part of an upgrade or migration. If the victim follows this instruction and transfers their assets into it, they essentially “poison” their wallets, enabling the threat actors to access and drain them.
Coinbase-themed email with seeds for the victim to use Source: SilentPush
That is because, when creating a new wallet, the victim isn’t using a secure, pre-generated seed phrase from the company (Coinbase) like they are made to believe, but instead using one for a wallet already under the attackers’ control.
Transferring their crypto into that wallet is basically handing over all their digital assets to the attacker, who can then transfer the funds out.
The best way to deal with urgent requests arriving via email is to ignore them and independently (not by clicking on the embedded links) log in to the claimed platform and check if there are any pending alerts for your account.
Cryptocurrency wallet users should never use a seed phrase provided by someone else, as a legitimate platform will never send a pre-generated seed phrase. Users should always generate their own seed phrases when creating a new wallet and never share them with anyone else.
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the ...
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.