Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbers

요약:Rapid7 unveiled Operation Asterix, a phishing campaign targeting roughly 885,000 phone numbers to steal cryptocurrency investors‘ assets. The campaign matched 5,576 accounts to Binance users and included fake Crypto.com emails; the largest file contained 316,002 German numbers, with additional directories covering Hong Kong, Bulgaria, the UK, the US, Canadian fintech firms, and Ledger-related lists. Attackers used fake apps impersonating Ledger, Trezor, and Exodus, plus fake support emails and phone calls, to steal seed phrases. The campaign achieved about a 13.6% “hit rate,” validating 43,066 exchange accounts from the German dataset, and also included a Kraken checker. AI tools were reportedly used. Separately, phishing and social engineering drove $306 million of the crypto industry’s $482 million in Q1 losses, per Hacken.

Cybersecurity firm Rapid7 unveiled a new cryptocurrency phishing campaign known as Operation Asterix, targeting roughly 885,000 phone numbers from several countries to steal cryptocurrency investors assets.

The phishing campaign led to 5,576 accounts matched to users on crypto exchange Binance, which were queued for attack, while the recovered logs also showed fake emails impersonating Crypto.com, according to a Monday report by Rapid7.

Of the 885,000 phone numbers, the largest file included 316,002 German mobile numbers, with additional directories covering Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and additional Ledger-related lists.

Phishing attacks and social engineering scams drove the majority of the crypto industrys losses in the first quarter of the year, accounting for $306 million out of the total $482 million lost, according to blockchain security company Hacken.

As part of the Asterix phishing campaign detailed by Rapid7 analysts Anna Sirokova and Jan Recinsky, attackers drove victims to fake apps impersonating Ledger, Trezor, and Exodus, seeking to steal their seed phrases. Attackers reached out to victims through fake support emails and phone inquiries.

Operation Aseterix kill chain from acquisition to exfiltration. Source: Rapid7.

Cointelegraph has contacted the analysts for further comment on what they found regarding target filtering, hardware wallet spoofing and self-custody vulnerabilities. We will update this article when they reply.

Earlier in August, wallet provider Trezor reported a breach of personal data affecting about 14,000 users through its shipping provider, ShipMonk.

In July, a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum.

In November 2023, a fake Ledger Live app on the Microsoft Store resulted in the theft of $588,000 across 38 transactions.

Related: DefiLlama delayed mobile launch over phishing apps on Apple Store, founder says

Asterix phishing campaign boasts 13% “hit rate”

Attackers matched 43,066 accounts to cryptocurrency users with exchange accounts, validated from the larger German dataset of over 316,000 phone numbers, meaning that the campaign has a “hit rate” of approximately 13.6%, according to Rapid7.

The report also identified a checker for Kraken, which sought to bulk-validate phone numbers against accounts from the cryptocurrency exchange. The cybersecurity company said that the recovered artifacts showed that artificial intelligence tools were used as a significant part of the phishing campaign.

Phishing attacks are a long-standing headwind for the crypto industry, as they enable attackers to exploit human behavior rather than the code of a protocol.

On May 25, onchain analyst “b-block” warned that scammers used Google to deploy malicious phishing ads impersonating decentralized exchange Uniswap, reportedly stealing more than $400,000 from victims.

Leading crypto industry figures, including Binance co-founder Changpeng Zhao, have previously called for better wallet security measures to avoid phishing scams, after an investor lost $50 million in an address poisoning scam in December 2025.

Magazine: How a ‘Wrong Number’ message turned into a $3.4M crypto scam

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

옵티미즘, 향후 에어드롭용 5억 4,690만 OP를 생태계 성장 기금으로 전환

다음

비트코인 ETF, 6.06억 달러 유입…5월 1일 이후 최대