Skip to main content

Cybersecurity Firm Maps Crypto Phishing Attack on 885,000 Numbers



Cybersecurity firm Rapid7 has disclosed a large-scale cryptocurrency phishing and vishing campaign dubbed “Operation Asterix,” designed to compromise crypto investors by impersonating popular wallet brands and luring victims to fraudulent applications.


In its report released this week, Rapid7 says attackers obtained data tied to roughly 885,000 phone numbers across multiple countries, then used exchange-account matching to identify targets—ultimately queuing thousands of victim accounts associated with Binance for follow-on attacks.



Key takeaways



  • Rapid7 estimates the campaign worked from a dataset of about 885,000 phone numbers, with a largest file containing 316,002 German mobile numbers.

  • Rapid7 found evidence of matching 5,576 accounts associated with Binance users, “queued for attack.”

  • Among validated exchange-linked targets, Rapid7 calculates an approximate 13.6% “hit rate” from the larger German dataset.

  • The scheme used impersonation tactics aimed at seed phrase theft, including fake prompts and support-style outreach.

  • Rapid7’s recovered artifacts indicate automated tooling, including use of AI, to support aspects of the campaign.



How Operation Asterix targets crypto users


Rapid7’s analysis, authored by Anna Sirokova and Jan Recinsky, describes how the attackers moved from acquisition of contact data to attempts at credential and seed phrase theft. The core technique involved directing victims to fake applications designed to impersonate wallets and wallet ecosystems.


According to the report, the fraudulent lures specifically referenced well-known self-custody brands including Ledger, Trezor, and Exodus. The attackers attempted to extract seed phrases by pushing victims toward the counterfeit software and accompanying “support” interactions.


Rapid7 also reports that outreach included both fake emails and phone-based inquiries, consistent with a phishing plus vishing workflow. In other words, the campaign wasn’t limited to a single lure method; it used layered contact channels to increase the odds of a victim engaging with the scam.



Target filtering and exchange-account matching


A major component of Rapid7’s findings is the apparent use of target filtering. The report indicates that the attackers matched 43,066 accounts connected to cryptocurrency users with exchange accounts, which were then validated against the larger set of over 316,000 German phone numbers. On that basis, Rapid7 calculates a “hit rate” of approximately 13.6% for the German dataset.


Rapid7’s findings go further by highlighting that the campaign included a checker for Kraken—used to bulk-validate phone numbers against accounts from that exchange. That implies the adversaries were not simply blasting contact lists; they were trying to confirm that particular numbers corresponded to exchange-registered identities before escalating.


For Binance specifically, Rapid7 says the campaign identified and queued 5,576 accounts for attack. The report frames this as a direct outcome of matching efforts tied to the wider phone-number dataset.



Seed-phrase theft via wallet spoofing


Rapid7’s recovered artifacts point to a strategy aimed squarely at self-custody weaknesses: the combination of wallet brand impersonation and human trust in “official” support channels. Rapid7 says victims were driven to fake apps that mimicked Ledger, Trezor, and Exodus, with the goal of stealing seed phrases.


This matters because seed phrases remain the highest-value target in many crypto theft attempts. Once a seed phrase is obtained, the attacker can often access the associated wallets without needing to bypass complex cryptography—making social engineering a uniquely effective attack surface in practice.


Rapid7’s report also notes that the campaign used AI tools as a significant part of operations. While the disclosure does not provide step-by-step details of how AI was applied, it supports the broader pattern that attackers increasingly rely on automation to scale personalization, message creation, and workflow management.



Why this fits the wider pattern of crypto fraud


Operation Asterix arrives amid a continued run of phishing and social engineering losses across the sector. Hacken, a blockchain security company, reported that phishing and social engineering scams accounted for $306 million of the $482 million lost in the first quarter of the year—according to Rapid7’s reference to Hacken’s figures.


That concentration underscores an ongoing asymmetry in crypto security: many of the most costly incidents still involve attackers exploiting user behavior rather than breaking protocol rules. In that environment, phone-number datasets and exchange-account matching can become especially dangerous, as they help scammers reach likely victims through direct, targeted contact.


The tactics described in Rapid7’s report also echo prior industry incidents: Cointelegraph previously reported on a Trezor customer data breach involving about 14,000 users via its shipping provider, ShipMonk, earlier in August; a nearly $1 million loss for an investor after signing a malicious phishing token approval transaction on Ethereum in July; and a fake Ledger Live app incident on the Microsoft Store in November 2023 that resulted in theft of $588,000 across 38 transactions.


Earlier onchain reporting has similarly highlighted how scammers can use mainstream platforms to distribute fake prompts; Cointelegraph has noted cases where malicious ads impersonating Uniswap appeared via Google, leading to losses reportedly exceeding $400,000.



What to watch next


Rapid7’s disclosure is likely to raise renewed attention on how attackers blend contact-data targeting with wallet brand impersonation and automated tooling. Investors and builders should watch for follow-on indicators such as new fake wallet app deployments and continued exchange-linked targeting methods, while the industry works toward reducing the human friction that scammers rely on.



https://www.cryptobreaking.com/cybersecurity-firm-maps-crypto-phishing-2/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Cybersecurity%20Firm%20Maps%20Crypto%20Phishing%20Attack%20on%20885,000%20Numbers%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...