Listen to this Post
A New Cyber Threat Targeting Crypto Users
A large-scale phishing campaign known as PoisonSeed is compromising corporate email marketing accounts to distribute fraudulent emails. These emails contain malicious crypto seed phrases, which unsuspecting users enter into their wallets—unwittingly handing over control of their assets to cybercriminals.
According to cybersecurity firm SilentPush, PoisonSeed primarily targets Coinbase and Ledger users by exploiting compromised accounts on platforms like Mailchimp, SendGrid, HubSpot, Mailgun, and Zoho. The attack follows a pattern seen in recent cybersecurity breaches, such as the Mailchimp hack involving security researcher Troy Hunt and the SendGrid compromise reported in March 2025.
While PoisonSeed bears some resemblance to attacks orchestrated by CryptoChameleon and Scattered Spider, SilentPush categorizes it separately due to distinct code variations and unique attack techniques.
How PoisonSeed Works: The Attack Chain
1. Identifying High-Value Targets:
The attackers first locate employees with access to CRM and bulk email platforms by analyzing marketing emails and newsletters.
2. Spear-Phishing Campaign:
The hackers send carefully crafted phishing emails from spoofed addresses, directing victims to fake login pages resembling legitimate services like Mailchimp.
3. Credential Theft:
Once an employee enters their credentials on the fake login page, the hackers gain access to their email marketing account.
4. Hijacking Email Lists:
Attackers export customer email lists and create new API keys to maintain unauthorized access—even if the legitimate owner resets their password.
5. Launching Crypto Phishing Attacks:
Using compromised email marketing accounts, the hackers send out phishing emails with alarming messages like:
– “Coinbase is transitioning to self-custodial wallets—follow these steps to secure your assets.”
6. Deploying Malicious Seed Phrases:
The phishing emails instruct victims to enter a pre-generated seed phrase into a new crypto wallet. However, this seed phrase belongs to a wallet already controlled by the attackers.
7. Draining the Funds:
As soon as the victim moves their cryptocurrency into the fraudulent wallet, the hackers seize control and transfer the funds out.
Preventing PoisonSeed Attacks
- Never trust unsolicited emails about account upgrades or wallet migrations.
- Manually visit official websites rather than clicking on links in emails.
- A legitimate crypto company will never send a pre-generated seed phrase.
- Always generate your own seed phrases and store them securely.
What Undercode Say: The Deeper Implications of PoisonSeed
- The Evolution of Cybercrime: From Passwords to Seed Phrases
Cybercriminals have shifted their focus from stealing passwords to stealing crypto wallets. Unlike traditional financial fraud, where stolen credentials can be reset, a compromised seed phrase is irreversible—once stolen, funds cannot be recovered. -
The Role of Email Marketing Platforms in Cybercrime
Mailchimp, SendGrid, and other platforms weren’t directly hacked—instead, their users were tricked into giving up access. This highlights the vulnerability of cloud-based marketing tools, which are now a prime target for cybercriminals.
3. The Growing Sophistication of Phishing Tactics
Phishing is no longer just about fake PayPal or banking emails. Attackers now use:
– Professionally designed login pages to mimic real platforms.
– Legitimate-sounding domains like `mailchimp-ssologin.com` to fool victims.
- Convincing narratives (e.g., “Coinbase security upgrade”) to trick even experienced crypto users.
4. Why Seed Phrases Are a Prime Target
Unlike passwords, seed phrases grant permanent control over a wallet. Once exposed, funds can be stolen instantly, and there’s no way to reverse the transaction—making them more valuable than credit card details on the dark web.
5. The Urgency Factor: How Hackers Exploit Fear
Phishing emails rely on urgency and fear to pressure victims into acting quickly. Messages like “Urgent security update required” or “Your assets will be frozen” push users to make mistakes. Recognizing these psychological tricks is key to avoiding scams.
6. The Need for Stronger Security Measures
Email providers and marketing platforms should implement:
– Multi-factor authentication (MFA) to prevent unauthorized logins.
- More robust detection systems for identifying phishing campaigns.
– Better user education on recognizing phishing attempts.
- The Future of Crypto Security: Beyond Seed Phrases
The PoisonSeed campaign exposes a critical flaw in seed phrase-based security. Future innovations might include:
– Hardware-based authentication instead of phrases.
– Biometric security measures for wallet access.
– Decentralized identity verification to prevent phishing-based attacks.
Final Thoughts: Who Is Responsible?
While individual users must stay vigilant, email marketing platforms, crypto exchanges, and regulators must also step up. The PoisonSeed attack demonstrates how a single compromised email account can lead to thousands of victims losing their life savings.
Fact Checker Results
- PoisonSeed is an ongoing, real campaign confirmed by SilentPush researchers and reported by cybersecurity sources like BleepingComputer.
- No legitimate crypto company (Coinbase, Ledger, etc.) sends pre-generated seed phrases—this is always a scam.
- Using compromised email marketing platforms to distribute phishing attacks is a known tactic used by multiple threat actors, including Scattered Spider.
References:
Reported By: https://www.bleepingcomputer.com/news/security/poisonseed-phishing-campaign-behind-emails-with-wallet-seed-phrases/
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
Undercode AI
Image Source:
Pexels
Undercode AI DI v2





