Recommended Free Tools
PoisonSeed is a phishing campaign that abuses compromised email-marketing and CRM accounts to send convincing crypto scams. Some messages impersonate Coinbase or Ledger and supply a wallet recovery phrase for the recipient to import. Because the attackers already know that phrase, they can control any wallet created from it and take funds sent there. Never use a recovery phrase supplied by an email, website, or another person.
What PoisonSeed is—and what it is not
Silent Push used the name PoisonSeed for a financially motivated campaign first publicly reported in April 2025. It is a campaign or actor label, not the name of a malware family or a conclusively identified criminal organization. The operation targets both organizations whose email or CRM accounts can be abused for distribution and cryptocurrency users who receive the resulting wallet lures. BleepingComputer’s April 2025 report and SecurityWeek’s coverage describe the campaign’s use of bulk-email and CRM services.
Reporting supports phishing and impersonation involving wallet brands; it does not establish that Coinbase’s or Ledger’s core systems were breached. The enabling abuse is closer to supply-chain-style misuse of trusted email distribution than a confirmed compromise of either wallet company.
How the PoisonSeed attack chain works
- Steal email-platform credentials. Attackers send convincing login lures to employees or administrators of services such as Mailchimp, SendGrid, HubSpot, Mailgun, or Zoho. Look-alike domains and cloned login pages can capture credentials. Later reporting described fake Cloudflare Turnstile or CAPTCHA-style pages used to make malicious sites seem credible; DomainTools documented those interstitials.
- Take over an account and its distribution tools. With stolen access, an attacker may export mailing lists, create or use API keys, and send campaigns through the compromised account. Silent Push linked the operation to the late-March 2025 compromise of Troy Hunt’s Mailchimp account and to an Akamai SendGrid incident reported that month, as described in Silent Push’s campaign post and the BleepingComputer report.
- Send through a channel recipients may trust. Messages can come through legitimate delivery infrastructure or a compromised business account. That can make familiar branding and a plausible sender less reassuring than usual.
- Push a wallet pretext. The email may claim that a provider is migrating wallets, requiring an upgrade, verifying an account, installing firmware, or recovering access. It directs the recipient to a phishing page or wallet workflow.
- Get the victim to use an attacker-known phrase. The page supplies a recovery phrase and tells the recipient to import it into a wallet. The phrase may be valid; the problem is that the attacker already knows it.
- Wait for the wallet to be funded. The attacker need not steal funds immediately. A delay can make the migration appear successful while the victim sends assets later. Campaign reporting and an Eventus Security advisory describe delayed theft as part of the risk.
Why the recovery phrase is the critical danger
A seed phrase, also called a recovery phrase or wallet backup, is a secret from which a wallet’s private keys can be recovered. It is not a verification code that a legitimate support agent needs to check your account. If another person provides the phrase, they can retain a copy and access wallets derived from it.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
- Phrase generated by your wallet: It can be safe to use if you created it through the authentic wallet application or device workflow and kept it secret.
- Phrase supplied by an email, website, or person: Treat it as attacker-controlled. Do not import it or send funds to an address derived from it.
- Your existing phrase entered into a website: Treat the wallet as compromised, even if the page looked genuine or nothing has been stolen yet.
- Recovery on a hardware wallet: Only proceed through the device’s authentic recovery process when you initiated it. A hardware device cannot make a phrase safe after it has been exposed.
Clicking a link alone is not the same as exposing a seed phrase. If you connected a wallet but did not enter a phrase, the concern may instead be a transaction approval, wallet-connect session, browser extension, or signed message. What matters is precisely what you entered, connected, or approved.
What the emails may claim
Reported lures have included Coinbase migration to self-custodial wallets, wallet upgrades or account transitions, Ledger firmware or security updates, and requests to create or import a wallet. The enterprise side also includes notices about restricted sending privileges or email-account verification. NVISO’s analysis and SecurityWeek’s reporting describe these kinds of pretexts.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Be wary of urgent instructions to migrate, restore, verify, or install an update from an email link. Open the official app or type the provider’s known domain yourself instead. A message passing SPF, DKIM, or DMARC checks does not prove its content is legitimate: authentication can show that a domain or service authorized the message, while the sending account itself may have been compromised.
Why compromised marketing accounts matter
A stolen CRM or bulk-email account can expose mailing lists and give attackers a plausible channel to reach customers, partners, or people unrelated to cryptocurrency. It can also be used to phish additional administrators or create new sending identities. Organizations outside the crypto sector may therefore become distribution victims even when the fraud ultimately targets wallet holders.
Rank #3
- Unparalleled Security: Protect your assets with EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Multi-share Backup eliminates single points of failure for secure cold wallet recovery
Silent Push reported targeting across Mailchimp, SendGrid, HubSpot, Mailgun, and Zoho. This is why the campaign is not just a fake-wallet-login story: the business account and its contact list can be the force multiplier. Email authentication remains useful, but account security, API governance, and careful verification of unexpected financial instructions matter too.
What is known about attribution and activity
Researchers have noted similarities between PoisonSeed and CryptoChameleon, Scattered Spider, and the wider “The Com” ecosystem. They have also identified differences in phishing-kit code and other infrastructure. Silent Push tracked PoisonSeed separately, and the public evidence cited here does not prove that Scattered Spider ran it. Treat any connection as tentative rather than established. See the DomainTools analysis and BleepingComputer’s account.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
NVISO reported observing the phishing kit in the wild from April 2025, and DomainTools described additional domains registered from June 2025 that appeared linked to continued activity. Those reports establish activity during 2025; they do not establish the campaign’s exact operational status today.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do if you encountered a PoisonSeed-style message
If you only received the email or clicked but entered nothing
- Do not reply, follow its links, or download attachments. Report it through your organization’s normal security channel or the email provider’s reporting feature.
- If you clicked but did not enter information, approve a transaction, or download anything, close the page and avoid further interaction. If you downloaded or ran a file, notify your security team or use a trusted device-support process to check the device.
- Navigate independently to the wallet or email provider’s official app or site if you need to verify an account notice.
If you entered email, CRM, or exchange credentials
- From a clean device, change the affected password and revoke active sessions or refresh tokens. Use the service’s official security settings or support channel.
- Turn on phishing-resistant multi-factor authentication where the service supports it, and check recovery methods and account activity for changes you did not make.
- If you reused that password elsewhere, change it on those services too. Do not assume that changing an email password fixes an exposed wallet phrase.
If you imported a supplied phrase but have not funded the wallet
- Do not send assets to it, and stop using it.
- Create a genuinely new wallet through the official wallet app or hardware-device workflow, generating a fresh recovery phrase yourself.
- Do not reuse the phrase from the email. Treat every address derived from that phrase as known to the attacker.
If you entered an existing phrase or sent funds
- Treat the wallet as compromised even if the balance is still intact. If assets remain transferable, move them promptly to a newly created wallet with a fresh phrase; do not sign unfamiliar transactions in the process.
- Where the relevant blockchain and wallet tools support it, revoke token approvals associated with the compromised wallet. This does not replace moving assets controlled by an exposed phrase.
- Preserve the email, message headers, suspicious domains, wallet addresses, transaction hashes, and timestamps. Contact the affected exchange or wallet provider through its official support channel and report theft to the relevant law-enforcement or cybercrime service.
- Ignore anyone promising to recover funds for an upfront fee. Recovery scams often target people immediately after a theft.
A small transfer does not make an exposed phrase safe: an attacker may monitor the wallet or wait for more funds. A hardware wallet is useful only when its keys and recovery phrase are generated and handled through a trusted workflow; it cannot undo exposure of a phrase the attacker already knows.
Best Value
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
If your organization’s email or CRM account was compromised
- Reset affected credentials from a clean device, then revoke active sessions and refresh tokens.
- Rotate API keys and integrations, and inspect for unauthorized users, administrators, webhooks, sending identities, and recovery changes.
- Review export logs for mailing-list downloads and campaign history or sent mail for unauthorized messages.
- Notify customers and partners if malicious messages were sent, and preserve authentication, API, and campaign logs.
- Enable phishing-resistant MFA where supported; inventory API keys, limit their permissions, and set expiry or rotation controls.
- Alert on bulk-list exports and new sending identities, and review sender authentication, look-alike-domain monitoring, and approval workflows for campaigns.
Silent Push recommendations reproduced in Intertec’s advisory include blocking known malicious domains, strengthening email security, and auditing or revoking suspicious API keys.
Indicators and detection clues
Silent Push reported finding 49 related domains through phishing-kit fingerprinting and WHOIS pivots. The following defanged examples were reported in campaign coverage; they are indicators to check against dated threat-intelligence feeds, not a guarantee that a domain is currently malicious. Domains can become inactive, be re-registered, or otherwise change status.
sso-account[.]commailchimp-sso[.]comfirmware-server12[.]comconnect1-coinbase[.]comswallet-coinbase[.]comhubservices-crm[.]comserver9-sendgrid[.]netresponsesendgrid[.]com
Additional behavioral clues reported by analysts include:
- Look-alike domains for email platforms or wallet brands, or a fake CAPTCHA/Cloudflare verification interstitial.
- URLs that contain an encoded or encrypted recipient email address.
- Unexpected API paths such as
/apior/api/2fa/verifyin a suspicious login flow. - Unusual mailing-list exports, newly created API keys or sending identities, or cryptocurrency-themed campaigns from an account that normally sends unrelated marketing.
DomainTools’ domain analysis and the Intertec indicator summary provide further context. Use behavioral monitoring as well as blocklists, since a domain list can be incomplete or stale.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




