Skip to main content

Cybersecurity Firm Maps Crypto Phishing Campaign to 885,000 Numbers



Rapid7 has disclosed details of a large-scale cryptocurrency phishing operation dubbed “Operation Asterix,” designed to target people through phone and email lures that ultimately aim to extract crypto seed phrases. The campaign reportedly reached into datasets covering roughly 885,000 phone numbers across multiple regions, with the largest tranche tied to Germany.



In Rapid7’s investigation, the phishing workflow included targeting users connected to the Binance exchange, producing 5,576 accounts matched to exchange users that were queued for attack. The firm also found evidence of fake communications impersonating Crypto.com, highlighting how the operation blended vishing tactics with exchange-branded messaging.



Key takeaways



  • Rapid7 traced Operation Asterix to a dataset of about 885,000 phone numbers, with Germany the largest source (316,002 numbers).

  • The campaign identified 43,066 accounts tied to crypto exchange users and generated 5,576 Binance-matched targets for follow-on attacks.

  • Attackers used fake Ledger, Trezor, and Exodus applications to pressure victims into revealing seed phrases.

  • Rapid7’s artifacts suggest automated tooling, including “checker” logic for Kraken account validation, alongside AI-assisted components.



Operation Asterix: scale, filtering, and “hit rate”


Rapid7’s report describes Operation Asterix as a campaign built around “targeting” rather than indiscriminate spam. According to the firm, attackers matched 43,066 accounts to cryptocurrency users using data validated against the broader German dataset containing more than 316,000 mobile numbers. Rapid7 estimates this translates to an approximate “hit rate” of 13.6% for the validated matching process.



The company also points to recovered artifacts indicating a separate checker function aimed at bulk-validating phone numbers against accounts associated with Kraken. This matters because it suggests the operation was not limited to a single exchange or geography; instead, it used verification steps to determine which phone numbers were most likely to correspond to crypto users.



How victims were lured: impersonation and seed-phrase extraction


At the center of Rapid7’s findings is the social-engineering phase of the campaign. Analysts Anna Sirokova and Jan Recinsky write that the attackers attempted to move victims toward fake applications impersonating well-known self-custody brands, including Ledger, Trezor, and Exodus.



Rapid7 says victims were driven to these impersonation surfaces with the objective of obtaining seed phrases—an outcome that can permanently compromise funds if users enter them into attacker-controlled flows. The phishing operation also used direct contact channels: attackers reached out through fake support emails and phone inquiries designed to look legitimate.



Rapid7’s findings also emphasize the operational chain—how contact was established, which targets were selected, and how the campaign progressed toward data exfiltration. While the report focuses on observed behavior in artifacts recovered by the security team, the practical implication for users is straightforward: even when the message appears to come from a brand or support channel, the risk is highest when the interaction attempts to steer victims toward entering recovery information.



Binance and Crypto.com were among the exchanges impersonated


One of the most consequential elements in Rapid7’s disclosure is how the campaign narrowed down real exchange users. The report states that it identified 5,576 accounts matched to users on Binance that were queued for attack. Rapid7 also reports that recovered logs included fake emails impersonating Crypto.com.



For traders and long-term holders, this pairing of exchange-linked targeting with brand impersonation underscores a common problem: attackers often aim to compromise trust in familiar service identities. Rather than relying solely on generic phishing, Operation Asterix appears to have used verification steps and exchange references to increase the likelihood of a victim responding.



Rapid7’s account of the target composition further indicates that the campaign’s infrastructure included lists beyond Germany. The largest file contained 316,002 German mobile numbers, while additional directories reportedly covered phone numbers associated with regions including Hong Kong, Bulgaria, and the UK, alongside US and Canadian fintech-related lists and Ledger-related lists.



Broader crypto security context: a persistent human-layer threat


Operation Asterix lands in a wider pattern of crypto fraud that repeatedly exploits users rather than breaking underlying protocols. The article notes that, according to blockchain security company Hacken, phishing and social engineering drove most of the crypto industry’s losses in the first quarter, accounting for $306 million out of a reported total of $482 million lost.



This is consistent with earlier incidents referenced in the same material. For example, it points to a Trezor-related personal data breach involving its shipping provider ShipMonk reported in August, a separate Ethereum-related case in July where a crypto investor lost nearly $1 million after approving a malicious phishing token approval transaction, and a prior episode in November 2023 where a fake Ledger Live app placed on the Microsoft Store led to theft totaling $588,000 across 38 transactions.



Taken together, these examples reinforce that crypto users face two different—but overlapping—risk categories: technical compromise through malicious software and direct loss from social-engineering flows that trick users into granting access or revealing recovery material.



What to watch next


As Rapid7’s disclosure shows, campaigns like Operation Asterix increasingly combine datasets, exchange validation, and impersonation of popular self-custody brands—meaning the most urgent question for users isn’t only whether phishing exists, but whether attackers can improve their targeting accuracy. Investors should watch for follow-on reporting from security teams on the specific tooling and any indicators of compromise tied to the fake Ledger, Trezor, and Exodus lures, while continuing to treat unsolicited support messages and “wallet recovery” requests as high-risk until independently verified.



https://www.cryptobreaking.com/cybersecurity-firm-maps-crypto-phishing/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Cybersecurity%20Firm%20Maps%20Crypto%20Phishing%20Campaign%20to%20885,000%20Numbers%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...