AMP-RI “Here’s What’s Coming Up Next” Email With Bitcoin Transfer Link: Likely Mailchimp Signup Form Abuse

Warning: I received an unsolicited email with the subject “Here's what's coming up next” that appeared to be an AMP-RI mailing-list confirmation sent through Mailchimp.

What made the message suspicious was not the normal newsletter content. Near the bottom, the email reproduced information supposedly submitted through a signup form, and the Last Name field contained a Bitcoin-related scam message and an external link.

The external destination is omitted from this article for safety.

Details of the email


Subject: Here's what's coming up next

Displayed sender: AMP-RI <info@amp-ri.com>

Received: September 16, 2026

The email included the following text:

For your records, here is a copy of the information you submitted to us...

Email Address: [recipient address omitted]
First Name: Tricobis
Last Name: 1.1542 BITCOIN TRANSFER ON HOLD. CONFIRM HERE [external URL omitted]

Why this looks like signup-form abuse

This case is unusual because AMP-RI itself appears to be a real professional organization, and the email otherwise resembles an ordinary Mailchimp subscription message.

The suspicious Bitcoin text appears specifically inside the value recorded as the subscriber's Last Name. That strongly suggests that somebody may have submitted the recipient's email address to a newsletter form while placing the scam message and link into another form field.

The automated email then appears to have reproduced those submitted values back to the recipient.

This does not by itself mean that AMP-RI created the Bitcoin message, that AMP-RI intentionally sent a scam, or that its email account was hacked.

Mailchimp itself warns that signup forms can receive fake signups and recommends protections such as reCAPTCHA for embedded forms:

Mailchimp: Add an Embedded Signup Form to Your Website

The legitimate-looking sender does not make the inserted link safe

This example shows why checking only the displayed sender address is not always enough.

A legitimate organization and a legitimate email-marketing platform can potentially be used as part of an abuse chain if an attacker is able to submit another person's email address and attacker-controlled text through a public form.

In this case, the strongest warning sign is the completely unrelated message:

1.1542 BITCOIN TRANSFER ON HOLD. CONFIRM HERE

A newsletter signup confirmation has no legitimate reason to ask the recipient to confirm a Bitcoin transfer through an unrelated external link.

What to do if you receive this email

  • Do not click the Bitcoin-related link.
  • Do not enter cryptocurrency wallet information, passwords, recovery phrases, payment details, or personal information.
  • If you did not subscribe to the mailing list, you can report the message as spam and delete it.
  • Do not assume that every other link in the message is safe merely because the email contains legitimate Mailchimp or organization links.
  • If you need to contact the organization, reach its website independently rather than through the suspicious content in the email.

The notable feature of this incident is therefore not simply another Bitcoin spam message. It is the apparent use of a legitimate newsletter signup and automated email system to deliver attacker-controlled text to someone who did not submit that information themselves.

Comments

Popular posts from this blog

MetaMask phishing email from system@phrase.com: “Please set up your new sign option and link your email”

ArterioFlush Scam Email: Dr. Oz “Arterial Flush Ritual” and CBS News Claims

“URGENT: Watch before CNN removes this knee surgery video” — spam email from support@uploadboy.com