Cybersecurity researchers at Rapid7 have uncovered a sophisticated crypto fraud operation that used nearly 885,000 phone numbers, fake versions of popular wallet applications and AI-assisted development tools to target cryptocy users and steal their recovery seed phrases.
The campaign, dubbed Operation ASTERIX, went far beyond traditional mass phishing. Attackers first identified phone numbers connected to real cryptocy accounts, gathered additional information about potential victims and then used convincing customer support calls, phishing emails and counterfeit wallet software impersonating Trezor, Ledger and Exodus.
Rapid7 Labs researchers Anna Širokova and Jan Recinsky uncovered the operation after discovering a misconfigured web directory connected to the attacker’s infrastructure.
That mistake gave researchers an unusually detailed look inside the operation.
The exposed infrastructure reportedly contained:
Approximately 885,000 phone numbers
Fake Trezor Suite, Ledger Live and Exodus applications
Account-validation tools targeting Crypto.com, Binance and Kraken
Phishing panels and automated dialing scripts
Malware builds for Windows and macOS
Databases containing enriched information about potential victims
Logs showing the use of AI coding assistants during development
Rapid7 named the campaign Operation ASTERIX after Asterisk, an open-source communications platform found within the attacker’s infrastructure and used as part of its voice-phishing operation.
One of the most concerning parts of Operation ASTERIX was how attackers selected their victims.
Instead of randomly sending millions of phishing messages and hoping someone responded, the operators reportedly built tools capable of checking whether individual phone numbers were connected to actual cryptocy exchange accounts.
Rapid7 discovered a dataset containing 316,002 German mobile phone numbers. An automated tool checked those numbers against a Crypto.com account-verification endpoint and successfully identified 43,066 accounts.
That represents a hit rate of approximately 13.6%.
A separate tool targeted Kraken, while Ledger-related datasets were divided across 54 countries.
One recovered Binance lead panel reportedly contained another 5,576 validated crypto targets waiting to be contacted.
After identifying real cryptocy users, the attackers moved into the social-engineering phase.
Victims could receive fraudulent customer support emails and phone calls designed to convince them that something was wrong with their cryptocy accounts or wallets.
They were then directed toward counterfeit versions of legitimate wallet software.
Rapid7 recovered fake versions of:
Trezor Suite
Ledger Live
Exodus
The malicious applications were designed to look legitimate while attempting to convince victims to enter their wallet recovery phrases.
Once an attacker obtains a recovery phrase, they can potentially recreate the victim’s wallet on another device and transfer the cryptocy without needing the original hardware wallet.
That makes a seed phrase one of the most sensitive pieces of information a cryptocy holder possesses.
Operation ASTERIX also demonstrates how artificial intelligence tools can potentially increase the capabilities of cybercriminals.
Rapid7 found logs showing that the operator used AI coding assistants while developing parts of the campaign.
Researchers found evidence involving tools including GitHub Copilot and Claude Code for tasks related to processing data, developing software and debugging parts of the attack infrastructure.
When one AI system reportedly refused to assist with certain code-obfuscation requests, the attacker moved to another AI model and attempted to bypass its safety restrictions using a jailbreak prompt.
Rapid7 could not determine whether that particular attempt succeeded.
The discovery illustrates an emerging cybersecurity concern. AI tools capable of helping legitimate developers build software faster can potentially provide similar productivity benefits to malicious actors attempting to create phishing infrastructure and counterfeit applications.
Operation ASTERIX was particularly sophisticated because attackers did not depend on a single method.
They combined traditional phishing with vish
Instead of receiving only a suspicious email, a potential victim could also receive a phone call from someone impersonating customer support.
Because attackers had already verified that the victim used a cryptocy service and could possess additional personal information about them, the phone call could appear significantly more convincing than a typical scam.
The basic attack chain worked like this:
Collect large databases of phone numbers.
Determine which numbers are associated with real crypto accounts.
Enrich those targets with additional personal information.
Contact victims through phishing emails or fraudulent support calls.
Direct victims toward counterfeit wallet applications.
Convince victims to enter their recovery phrases.
Send the stolen information back to infrastructure controlled by the attackers.
The discovery comes shortly after a separate security incident involving Trezor customers.
Earlier this month, a breach involving Trezor shipping provider ShipMonk exposed personal information belonging to nearly 14,000 customers.
Nearly 12,000 customers reportedly had information including their phone numbers and shipping addresses exposed.
There is currently no evidence establishing that the ShipMonk breach is connected to Operation ASTERIX.
However, incidents involving leaked customer information demonstrate why personal data connected to cryptocy ownership can be particularly valuable to criminals.
Once attackers know that a specific individual owns cryptocy, information such as a phone number, email address or home address can potentially be used to construct much more targeted scams.
Operation ASTERIX reinforces one of the most important security rules in cryptocy.
Never give your recovery seed phrase to someone claiming to represent a wallet provider, cryptocy exchange or customer support department.
Crypto users should also take several precautions:
Download wallet software only through the wallet provider’s verified official website or official app listing
Never enter a seed phrase because of an unsolicited phone call, text message or email
Verify customer support contacts independently rather than using links supplied in unexpected messages
Treat urgent warnings claiming your wallet is compromised with extreme caution
Use hardware security keys or authenticator apps for exchange accounts when available
Assume that a caller knowing your name, phone number or exchange provider does not prove they are legitimate
Most importantly, a recovery phrase should be treated like the master key to the cryptocy stored in a wallet.
MapleStory Universe is putting artificial intelligence in the hands of game creators with the launch…
Kalshi is making another major move beyond prediction markets, filing with the Commodity Futures Trading…
Coinbase is bringing high-leverage decentralized derivatives directly into its Base App through an integration with…
Hong Kong's first regulated Hong Kong dollar stablecoin is moving beyond testing and into real-world…
The highly anticipated launch of $CLOCKIN on StonkBroker’s Stonk Launcher has come under scrutiny after…
A new NFT collection on Robinhood Chain is attempting to redefine what an NFT can…