How Did Operation ASTERIX Target Crypto Investors?
Cybersecurity firm Rapid7 has uncovered a cryptocurrency phishing campaign that collected roughly 885,000 phone numbers and used account-validation tools, fake support messages and counterfeit wallet applications to identify and attack crypto investors.The campaign, tracked as Operation ASTERIX, included phone-number datasets from several countries. The largest file contained 316,002 German mobile numbers, while other directories covered Hong Kong, Bulgaria, the UK, the US, Canadian fintech users and lists associated with Ledger customers across multiple countries.Rather than contacting the entire dataset at random, the attackers used automated tools to determine which phone numbers were associated with cryptocurrency accounts. Rapid7 found 43,066 confirmed crypto accounts within the German dataset alone, equivalent to a hit rate of about 13.6%.The recovered infrastructure also contained a Binance lead panel showing 5,576 validated crypto targets queued for attack. Separate tooling was designed to check phone numbers against Kraken accounts, while other recovered material included fake emails impersonating Crypto.com and Binance.This filtering made the campaign more dangerous than broad phishing attempts because attackers could concentrate their resources on people already known or strongly suspected to own digital assets.
How Were Attackers Trying To Steal Crypto?
Operation ASTERIX combined phishing emails with voice calls and counterfeit cryptocurrency wallet software. Victims could first receive an email appearing to come from a legitimate crypto company before being contacted by someone impersonating customer support.The attackers could reference information obtained during the account-validation process, including names, phone numbers, locations and exchange associations. That information made support calls appear more credible and increased the chance that victims would follow instructions.Targets were then directed toward fake applications impersonating Ledger, Trezor and Exodus. The applications were designed to capture wallet recovery phrases, which can provide complete control over cryptocurrency held in a self-custody wallet.The operation therefore targeted a weakness that technical security measures cannot fully eliminate: convincing the asset owner to voluntarily provide the credentials needed to move the funds.That risk has become an important source of crypto losses. Hacken reported that phishing and social engineering accounted for $306 million of the roughly $482 million stolen across the industry during the first quarter of 2026.
Investor Takeaway
What Role Did AI Play In The Campaign?
Rapid7 also found evidence that artificial intelligence coding assistants were used extensively while the attackers developed and maintained the operation.Recovered material showed AI tools being used to package applications, modify phishing infrastructure, troubleshoot software builds and obfuscate malicious code. The attackers also attempted to bypass safety controls when an AI system resisted parts of the development process.The use of AI does not create a fundamentally new form of phishing, but it can reduce the technical work required to build and modify malicious infrastructure. Attackers can potentially produce convincing applications, adapt campaigns and troubleshoot software more quickly without needing the same level of specialized expertise.For cryptocurrency users, that could increase the volume and sophistication of scams while making visual appearance a weaker indicator of whether an application or support interaction is legitimate.
Why Are Phishing Attacks Difficult For Crypto Investors?
Cryptocurrency phishing has remained effective because transactions are often irreversible and self-custody places control directly with the user. Once an attacker obtains a valid recovery phrase or persuades a victim to approve a malicious transaction, recovering the assets can be extremely difficult.Recent incidents show the range of techniques being used. A crypto investor lost nearly $1 million in July after approving a malicious token transaction on Ethereum, while a counterfeit Ledger Live application distributed through the Microsoft Store previously resulted in $588,000 being stolen across 38 transactions.The ASTERIX operation adds another concern: attackers increasingly appear able to combine data from several sources before approaching a victim. Someone receiving a call from a supposed exchange representative may therefore hear accurate details about their account or personal information even though the caller has no legitimate connection to the platform.That makes independent verification more important. Investors should avoid providing recovery phrases under any circumstances and should access wallet or exchange software through independently verified official channels rather than links supplied through unsolicited emails or calls.For exchanges and wallet providers, the campaign also increases pressure to prevent account-enumeration tools from confirming whether phone numbers belong to existing customers. Reducing that information leak can make it harder for attackers to convert large datasets into targeted lists of known cryptocurrency holders.
