Home » Fake Trezor, Ledger and Exodus Apps Target Crypto Users in Massive Seed Phrase Scam

Fake Trezor, Ledger and Exodus Apps Target Crypto Users in Massive Seed Phrase Scam

by Terron Gold
0 comments

Cybersecurity researchers at Rapid7 have uncovered a sophisticated crypto fraud operation that used nearly 885,000 phone numbers, fake versions of popular wallet applications and AI-assisted development tools to target cryptocurrency users and steal their recovery seed phrases.

The campaign, dubbed Operation ASTERIX, went far beyond traditional mass phishing. Attackers first identified phone numbers connected to real cryptocurrency accounts, gathered additional information about potential victims and then used convincing customer support calls, phishing emails and counterfeit wallet software impersonating Trezor, Ledger and Exodus

Operation ASTERIX Targeted Nearly 885,000 Phone Numbers

Rapid7 Labs researchers Anna Širokova and Jan Recinsky uncovered the operation after discovering a misconfigured web directory connected to the attacker’s infrastructure.

That mistake gave researchers an unusually detailed look inside the operation.

The exposed infrastructure reportedly contained:

  • Approximately 885,000 phone numbers

  • Fake Trezor Suite, Ledger Live and Exodus applications

  • Account-validation tools targeting Crypto.com, Binance and Kraken

  • Phishing panels and automated dialing scripts

  • Malware builds for Windows and macOS

  • Databases containing enriched information about potential victims

  • Logs showing the use of AI coding assistants during development

Rapid7 named the campaign Operation ASTERIX after Asterisk, an open-source communications platform found within the attacker’s infrastructure and used as part of its voice-phishing operation. 

Hackers Checked Who Actually Owned Crypto Before Calling

One of the most concerning parts of Operation ASTERIX was how attackers selected their victims.

Instead of randomly sending millions of phishing messages and hoping someone responded, the operators reportedly built tools capable of checking whether individual phone numbers were connected to actual cryptocurrency exchange accounts.

Rapid7 discovered a dataset containing 316,002 German mobile phone numbers. An automated tool checked those numbers against a Crypto.com account-verification endpoint and successfully identified 43,066 accounts.

That represents a hit rate of approximately 13.6%

A separate tool targeted Kraken, while Ledger-related datasets were divided across 54 countries.

One recovered Binance lead panel reportedly contained another 5,576 validated crypto targets waiting to be contacted. 

Fake Trezor and Ledger Apps Stole Recovery Phrases

After identifying real cryptocurrency users, the attackers moved into the social-engineering phase.

Victims could receive fraudulent customer support emails and phone calls designed to convince them that something was wrong with their cryptocurrency accounts or wallets.

They were then directed toward counterfeit versions of legitimate wallet software.

Rapid7 recovered fake versions of:

  • Trezor Suite

  • Ledger Live

  • Exodus

The malicious applications were designed to look legitimate while attempting to convince victims to enter their wallet recovery phrases. 

Once an attacker obtains a recovery phrase, they can potentially recreate the victim’s wallet on another device and transfer the cryptocurrency without needing the original hardware wallet.

That makes a seed phrase one of the most sensitive pieces of information a cryptocurrency holder possesses.

AI Tools Were Used to Help Build the Attack

Operation ASTERIX also demonstrates how artificial intelligence tools can potentially increase the capabilities of cybercriminals.

Rapid7 found logs showing that the operator used AI coding assistants while developing parts of the campaign.

Researchers found evidence involving tools including GitHub Copilot and Claude Code for tasks related to processing data, developing software and debugging parts of the attack infrastructure. 

When one AI system reportedly refused to assist with certain code-obfuscation requests, the attacker moved to another AI model and attempted to bypass its safety restrictions using a jailbreak prompt.

Rapid7 could not determine whether that particular attempt succeeded. 

The discovery illustrates an emerging cybersecurity concern. AI tools capable of helping legitimate developers build software faster can potentially provide similar productivity benefits to malicious actors attempting to create phishing infrastructure and counterfeit applications.

The Attack Combined Phishing With Vishing

Operation ASTERIX was particularly sophisticated because attackers did not depend on a single method.

They combined traditional phishing with vishing, or voice phishing.

Instead of receiving only a suspicious email, a potential victim could also receive a phone call from someone impersonating customer support.

Because attackers had already verified that the victim used a cryptocurrency service and could possess additional personal information about them, the phone call could appear significantly more convincing than a typical scam.

The basic attack chain worked like this:

  1. Collect large databases of phone numbers.

  2. Determine which numbers are associated with real crypto accounts.

  3. Enrich those targets with additional personal information.

  4. Contact victims through phishing emails or fraudulent support calls.

  5. Direct victims toward counterfeit wallet applications.

  6. Convince victims to enter their recovery phrases.

  7. Send the stolen information back to infrastructure controlled by the attackers. 

Recent Trezor Data Breach Adds Another Security Concern

The discovery comes shortly after a separate security incident involving Trezor customers.

Earlier this month, a breach involving Trezor shipping provider ShipMonk exposed personal information belonging to nearly 14,000 customers.

Nearly 12,000 customers reportedly had information including their phone numbers and shipping addresses exposed. 

There is currently no evidence establishing that the ShipMonk breach is connected to Operation ASTERIX.

However, incidents involving leaked customer information demonstrate why personal data connected to cryptocurrency ownership can be particularly valuable to criminals.

Once attackers know that a specific individual owns cryptocurrency, information such as a phone number, email address or home address can potentially be used to construct much more targeted scams.

Crypto Users Should Never Share Their Seed Phrase

Operation ASTERIX reinforces one of the most important security rules in cryptocurrency.

Never give your recovery seed phrase to someone claiming to represent a wallet provider, cryptocurrency exchange or customer support department.

Crypto users should also take several precautions:

  • Download wallet software only through the wallet provider’s verified official website or official app listing

  • Never enter a seed phrase because of an unsolicited phone call, text message or email

  • Verify customer support contacts independently rather than using links supplied in unexpected messages

  • Treat urgent warnings claiming your wallet is compromised with extreme caution

  • Use hardware security keys or authenticator apps for exchange accounts when available

  • Assume that a caller knowing your name, phone number or exchange provider does not prove they are legitimate

Most importantly, a recovery phrase should be treated like the master key to the cryptocurrency stored in a wallet.

You may also like

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?

This website uses cookies to improve your experience. To read more or opt here visit the privacy policy. Accept Read More