Rapid7 says Operation Asterix targeted 885,000 phone numbers in crypto phishing push

Rapid7 says Operation Asterix targeted 885,000 phone numbers in crypto phishing push

N
News Editor
2026-08-20 12:35:32
Cybersecurity firm Rapid7 has identified a cryptocurrency phishing operation, dubbed Operation Asterix, that targeted about 885,000 phone numbers across several jurisdictions in an attempt to steal investors’ assets. According to Rapid7, the campaign redirected victims to spoofed wallet provider sites and fake wallet apps, while recovered logs also showed fraudulent emails impersonating Crypto.com. The firm said 5,576 accounts matched to Binance users were queued for attack, and the largest dataset in the campaign contained 316,002 German mobile numbers. Additional directories covered Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and Ledger-linked lists. Rapid7 analysts Anna Sirokova and Jan Recinsky said the attackers impersonated Ledger, Trezor and Exodus and used fake support emails and phone calls to trick users into handing over seed phrases. From the German dataset alone, 43,066 accounts were matched to exchange users, implying a 13.6% hit rate. Rapid7 also found a Kraken checker used to bulk-validate phone numbers against exchange accounts and said AI tools played a major part in the campaign.

Cybersecurity firm Rapid7 has disclosed a cryptocurrency phishing campaign called Operation Asterix that targeted roughly 885,000 phone numbers across several countries. The goal was to redirect crypto investors to fake wallet provider websites and steal their holdings.

Rapid7 says Operation Asterix targeted 885,000 phone numbers in crypto phishing push 2

In a Monday report, Rapid7 said the campaign produced 5,576 accounts matched to users on crypto exchange Binance, and those accounts were queued for attack. Recovered logs also showed fake emails impersonating Crypto.com.

Of the 885,000 phone numbers, the largest file contained 316,002 German mobile numbers. Other directories covered Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and additional Ledger-related lists.

Rapid7’s findings came against a broader backdrop of phishing-related losses in crypto. Blockchain security company Hacken said phishing attacks and social engineering scams accounted for $306 million of the $482 million lost by the industry in the first quarter of the year.

Fake wallet apps and support outreach formed part of the campaign

Rapid7 analysts Anna Sirokova and Jan Recinsky said attackers behind Asterix pushed victims toward fake apps impersonating Ledger, Trezor and Exodus. The objective was to obtain seed phrases. Victims were approached through fake support emails and phone inquiries.

Rapid7 also published a kill chain describing the operation from acquisition to exfiltration.

Rapid7 says Operation Asterix targeted 885,000 phone numbers in crypto phishing push 3

Cointelegraph said it had contacted the analysts for more detail on target filtering, hardware wallet spoofing and self-custody vulnerabilities, and that the story would be updated if they replied.

Rapid7 put the hit rate at about 13.6%

According to the report, attackers matched 43,066 accounts to cryptocurrency users with exchange accounts from the larger German dataset of more than 316,000 phone numbers. Rapid7 said that translates to a hit rate of about 13.6%.

The report also identified a checker for Kraken, designed to bulk-validate phone numbers against accounts at the exchange. Rapid7 said recovered artifacts indicated that artificial intelligence tools were used as a significant part of the phishing campaign.

The company added that phishing remains a persistent problem for the crypto sector because it exploits human behavior rather than flaws in protocol code.

Other incidents cited in the report

Earlier in August, wallet provider Trezor reported a personal data breach affecting about 14,000 users through its shipping provider, ShipMonk.

Rapid7 says Operation Asterix targeted 885,000 phone numbers in crypto phishing push 4

In July, a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum.

In November 2023, a fake Ledger Live app on the Microsoft Store led to the theft of $588,000 across 38 transactions.

On May 25, onchain analyst 「b-block」 warned that scammers used Google to place malicious phishing ads impersonating decentralized exchange Uniswap, reportedly stealing more than $400,000 from victims.

Prominent figures in the crypto industry, including Binance co-founder Changpeng Zhao, have previously called for stronger wallet security measures to reduce phishing risk after an investor lost $50 million in an address poisoning scam in December 2025.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
80

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.