Share this article

Phishing Scam Targets US Marshals Service Bitcoin Auction List

The attack targeted individuals on the leaked Silk Road auction email list, successfully stealing 100 BTC.

Updated May 9, 2023, 3:02 a.m. Published Jul 4, 2014, 4:46 p.m.
Hacker

Individuals on the recipients list of the leaked US Marshals Service email to Silk Road auction enquirers are being targeted in a phishing attack, and at least one individual has fallen for the scam.

The Wall Street Journal confirmed that several individuals on the list received phishing emails from the same source. However, not all the individuals on the leaked email recipients list were targeted.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The unfortunate victim of the attack was Sam Lee of bitcoin arbitrage fund Bitcoins Reserve, which lost 100 BTC as a result.

The funds were sent by the firm's chief technology officer, Jim Chen, after he received what seemed like an email request to do so from Lee. In fact, the funds ended up being sent outside the company to the attacker's wallet. The transaction can be seen here, according to Lee.

Operational oversight

Lee said that the funds he had been scammed out of were owned by Bitcoins Reserve and that he used personal funds to replace them. He informed Bitcoins Reserve investors about the situation in an email, saying:

"As this attack vector was only successful due to an oversight in operations, the founders of Bitcoins Reserve will compensate the company by injecting an additional 100 Bitcoins to ensure we're still effectively performing arbitrage for our investors."

How they did it

The complete procedure for the scam was complicated and extremely sophisticated, but the basic process was as follows.

Lee received an email on 21st June from a certain 'Linda Jackson' claiming to represent BitFilm Production, a genuine company based in Germany. Jackson falsely claimed that the firm was assembling a series of interviews about the impending auction for a client.

Jackson then sent Lee a second email containing a link that directed to a file containing the questions for the interviews. This appeared to be a Google Drive document, but was actually a website controlled by the attacker.

The faked page then requested Lee's email password to gain access to the document, and consequently, when the password was entered, the attacker gained access to Lee's email accounts.

The scammers finally sent an email, purporting to be from Lee, to various employees requesting funds be sent to an external bitcoin wallet address, and the CTO unsuspectingly complied.

Facts agree

Lee's version of the story, and the emails from the attacker corroborating it (which CoinDesk has been given access to), mirror the phishing method described in the WSJ article.

The Journal also reported that while BitFilm Production is a real company, it had never attempted to contact the individuals on the leaked email.

The US Marshals Service has since issued a statement, saying that individuals affected by phishing scams should contact the appropriate law enforcement authorities, noting that the FBI dealt with phishing scams in the United States.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Turkey's Paribu Buys CoinMENA in $240M Deal, Expanding Into High-Growth Crypto Markets

Yasin Oral, Founder and CEO of Paribu (center) and Dina Sam’an (left) and Talal Tabbaa (right), Co-Founders of CoinMENA (Paribu, modified by CoinDesk)

With the acquisition, Paribu gains regulatory foothold in Bahrain and Dubai and access to the region's fast-growing crypto user base.

What to know:

  • Paribu acquires Bahrain- and Dubai-based CoinMENA for up to $240 million.
  • Deal marks Turkey’s biggest fintech acquisition and first international crypto M&A, the firm said.
  • The move taps into the MENA region’s fast-growing crypto user base and supportive regulatory hubs.