In October 2024, a Paris-based investor lost access to his Binance account. He received an alert SMS: someone had just modified his security email address. Yet he had enabled two-factor authentication (MFA) for months. The whole thing happened in less than three minutes, without him validating anything. The criminal used Starkiller, a phishing service specialized in bypassing MFA, accessible on Telegram for $200 per month.
This case is far from isolated. According to Chainalysis data for 2024, $3.2 billion was stolen through crypto scams, with an increasing share linked to MFA phishing attacks. The problem no longer stems from users failing to secure their accounts. It comes from the industrialization of cybercriminal ransomware services, transforming methods once reserved for experienced hackers into tools accessible to everyone.
The industrialization of MFA bypass
Multi-factor authentication seemed like the ultimate solution. A password, then a code received by SMS or generated by an app: two successive barriers that should effectively protect your access. This logic still holds against classic brute-force attacks or database breaches. But it collapses against a new generation of MFA bypass phishing tools.

Starkiller, Evilginx, Modlishka: these names mean nothing to the general public, but they've become references on underground forums. These platforms operate on a real-time interception attack principle, called man-in-the-middle. Concretely, the criminal creates a perfect copy of your exchange platform's login page (Binance, Kraken, Coinbase). When you enter your credentials and then your MFA code, the system instantly transmits this information to the real site while redirecting you. You're logged in, so is the criminal. The MFA code was valid for just a few seconds, long enough for the attacker to capture your authenticated session.
What's different from old phishing methods? In the past, you needed solid technical skills to create these malicious pages and manage the necessary server infrastructure. Today, Starkiller offers an all-in-one interface. You choose the target platform from a dropdown menu, customize your bait message, and the system automatically generates the malicious link. The service handles hosting, SSL certificates (which give the appearance of a secure site with the green padlock), and even automated phishing message delivery via email or SMS.
A cybercriminal ransomware business model
These platforms operate on a monthly subscription model, ranging from $150 to $400 depending on features. Some even offer customer support, video tutorials, and regular updates when exchange platforms modify their login interfaces. We're witnessing a genuine economy of cybercriminal ransomware services, where technical specialization becomes a commercialized product.
This industrialization has a direct impact: attack numbers are exploding because the technical barrier to entry disappears. A criminal with no particular IT knowledge can now launch targeted phishing campaigns. Underground forums are full of Starkiller users boasting about compromising dozens of accounts in just a few weeks.
The red flags you should watch for
Facing this threat, certain signals should immediately grab your attention. These indicators don't guarantee an attack is underway, but they justify systematic verification before taking any action.
1. Urgent messages about your account security. You receive an email or SMS telling you that suspicious activity has been detected and you must verify your account immediately. The message contains a clickable link. This scenario represents 73% of MFA phishing attempts recorded by CERT-FR in 2024. Legitimate platforms send you alerts, but they never ask you to click a link to resolve the issue. They invite you to log in yourself via the official app or website.
2. The slightly modified URL. Criminals use domain names very similar to the original: binance-secure.com, kraken-verify.net, coinbase-support.org. These variations are often undetectable to the naked eye, especially on mobile where the full URL isn't always displayed. Some services like Starkiller automate the purchase of these domains and generation of valid SSL certificates, making the scam even more credible.
3. A request for MFA code just after login. If you just logged in normally to your platform, no particular action has been initiated on your end, and you suddenly receive an MFA validation request, stop everything. This scenario typically corresponds to a criminal who has just intercepted your credentials and is trying to validate their own login by making you believe it's routine verification.
4. Login pages that redirect you multiple times. One victim describes this experience: after entering her credentials and MFA code, the page displayed a generic error message ("Login impossible, please try again"), then redirected her to Binance's real login page. Meanwhile, the criminal had already captured the authenticated session. This redirection technique masks the attack by making it seem like a simple temporary glitch.
What to do if you're affected
If you suspect your credentials have been compromised or if you clicked on a suspicious link, your speed of reaction becomes critical. Criminals act very quickly once they have your session, sometimes within minutes. Protecting your exchange account requires immediate reflexes.
Immediate action #1: Change your password from a trusted device. Don't use the device from which you clicked the suspicious link. Log in from another computer or phone, directly via the official app or by manually typing the URL in your browser. Change your password immediately. This invalidates all active sessions, including the criminal's if they haven't already modified security settings.
Immediate action #2: Revoke all active sessions. Most exchange platforms offer a "Logout all devices" function in security settings. Enable it systematically. Also check the list of recently connected IP addresses: if you spot an unusual location (login from a foreign country when you haven't traveled), document this information.
Immediate action #3: Check your pre-registered withdrawal addresses. Criminals frequently add their own wallet addresses to your withdrawal whitelist, sometimes by slightly modifying an existing address. Delete any address you don't formally recognize. If withdrawals have already been made, note the destination addresses and exact amounts.
Action #4: File a complaint and report to PHAROS. Even if recovery chances are low, the official complaint remains necessary. It constitutes legal evidence in case of disputes with your platform or insurer. Also report the scam on the PHAROS platform (Platform for Harmonization, Analysis, Cross-referencing and Routing of Reports), managed by the Ministry of the Interior. These reports feed authorities' databases and can help identify criminal networks.
Action #5: Enable withdrawal whitelists and security delays. Most exchange platforms let you define a list of authorized withdrawal addresses, with a 24 to 48-hour validation delay for any newly added address. This often-overlooked feature is your best protection. Even if a criminal gains access to your authenticated session, they won't be able to withdraw your assets to a previously unapproved address. This security delay gives you time to react. To understand other vulnerabilities related to digital asset security, check out our analysis on how hackers bypass hardware wallet security and how to protect yourself.
Strengthening your multi-factor authentication security
Multi-factor authentication remains essential protection, but it's no longer sufficient against real-time MFA phishing interception attacks. Vigilance must now focus on three complementary elements: systematic URL verification before any login, enabling withdrawal whitelists with security delays, and absolute distrust of any message containing a clickable link, even if it appears to come from your platform.
Criminals exploit a psychological blind spot: we've learned to trust MFA as the ultimate guarantee. Yet this trust becomes a vulnerability when it makes us drop our guard. A validated MFA code doesn't mean you're on the right site. It simply means you've proven your identity to someone, but that someone isn't necessarily the legitimate platform.
Regulation is evolving. Article 67 of the MiCA Regulation now imposes strengthened security requirements on European platforms, notably strong authentication. Concretely, this means exchanges will gradually abandon SMS codes in favor of more robust solutions like physical security keys (FIDO2). But this transition will take time, and cybercriminal ransomware services are already adapting their techniques.
In the meantime, the rule remains simple: never click a link received by email or SMS to log into your crypto account. Type the URL yourself or use the official app. It's inconvenient, it's slower, but it's the only way to ensure you're really communicating with the right platform. Facing services like Starkiller, this discipline becomes your first line of defense. If you want to dive deeper into security issues in the crypto ecosystem, particularly regarding vulnerabilities to quantum computing, our detailed analysis examines emerging risks to your digital assets.



