All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Cybersecurity firm Rapid7 uncovers crypto phishing campaign targeting 885,000 phone numbers

Created at 20 Aug · 12:41 PM1 source↑ Market-relevant
IN SHORT

Cybersecurity firm Rapid7 has detailed Operation Asterix, a cryptocurrency phishing campaign that targeted approximately 885,000 phone numbers globally. The campaign aimed to steal assets by redirecting victims to fake wallet provider websites and impersonating legitimate crypto services.

Key Numbers

885,000phone numbers targeted
316,002German mobile numbers in largest dataset
5,576Binance accounts queued for attack
43,066accounts matched to crypto users
13.6%campaign hit rate
$306 millioncrypto losses from phishing in Q1
$482 milliontotal crypto losses in Q1

Who's Involved

Rapid7
Cybersecurity firm that unveiled Operation Asterix
Anna Sirokova
Rapid7 analyst detailing the Asterix campaign
Jan Recinsky
Rapid7 analyst detailing the Asterix campaign
Binance
Crypto exchange with matched user accounts
Crypto.com
Impersonated in fake emails
Ledger
Impersonated in fake apps
Trezor
Impersonated in fake apps
Exodus
Impersonated in fake apps
Kraken
Exchange with a checker identified in recovered artifacts
Changpeng Zhao
Binance co-founder calling for better wallet security

↳ Why This Matters

This operation highlights the persistent and evolving threat of phishing attacks within the cryptocurrency space, demonstrating the scale and sophistication attackers are employing, including the use of AI, to target investors and compromise their digital assets.

Key facts

  • Cybersecurity firm Rapid7 identified a cryptocurrency phishing campaign named Operation Asterix.
  • The campaign targeted 885,000 phone numbers across several countries, including Germany, Hong Kong, the UK, and the US.
  • Attackers used fake websites and emails impersonating legitimate wallet providers and exchanges like Ledger, Trezor, Exodus, and Binance.
  • The campaign achieved an estimated 13.6% "hit rate", matching over 43,000 accounts to cryptocurrency users.
  • Artificial intelligence tools were utilized in the phishing campaign.

Cybersecurity firm Rapid7 has detailed a large-scale cryptocurrency phishing campaign, dubbed Operation Asterix, which targeted approximately 885,000 phone numbers across multiple countries. The campaign's objective was to steal assets from cryptocurrency investors by luring them to fraudulent websites that mimicked legitimate wallet providers and exchanges.

According to Rapid7's report, the attackers employed fake emails and phone inquiries to impersonate services such as Crypto.com, Ledger, Trezor, and Exodus. The recovered logs indicated that 5,576 accounts linked to users on the crypto exchange Binance were identified as targets. The largest dataset of phone numbers included 316,002 German mobile numbers, with additional directories covering Hong Kong, Bulgaria, the UK, the US, and Canadian fintech companies, alongside Ledger-related lists.

Rapid7 analysts Anna Sirokova and Jan Recinsky highlighted that the campaign achieved a "hit rate" of approximately 13.6%, successfully matching 43,066 accounts to cryptocurrency users from the German dataset alone. The recovered artifacts also revealed a checker for Kraken, suggesting an attempt to validate phone numbers against accounts on that exchange.

Phishing attacks and social engineering scams have been a significant driver of losses in the cryptocurrency industry. In the first quarter of the year, these types of attacks accounted for $306 million out of a total of $482 million lost, according to blockchain security company Hacken. The report from Rapid7 also noted the use of artificial intelligence tools as a substantial part of the phishing campaign.

This campaign follows other notable incidents, including a data breach affecting about 14,000 Trezor users via its shipping provider, ShipMonk, and a crypto investor losing nearly $1 million due to a malicious phishing token approval transaction on Ethereum. In November 2023, a fake Ledger Live app on the Microsoft Store led to the theft of $588,000 across 38 transactions.

Phishing remains a persistent challenge for the crypto industry, as it exploits human behavior rather than protocol vulnerabilities. Earlier in May, scammers reportedly used malicious phishing ads impersonating Uniswap to steal over $400,000. Industry figures like Binance co-founder Changpeng Zhao have previously urged for enhanced wallet security measures to combat such scams.

Frequently asked questions

Operation Asterix is a cryptocurrency phishing campaign identified by cybersecurity firm Rapid7, which targeted approximately 885,000 phone numbers globally with the aim of stealing investors' digital assets.

Attackers used fake emails and phone inquiries to impersonate legitimate crypto services like Ledger, Trezor, and Exodus, directing victims to fake websites to steal their seed phrases and account information.

The campaign targeted 885,000 phone numbers, with the largest subset being 316,002 German mobile numbers. Rapid7 reported a hit rate of about 13.6%, matching over 43,000 accounts.

The recovered artifacts indicated that artificial intelligence tools were used as a significant part of the phishing campaign, suggesting increased sophistication in the attack methods.

What Happens Next

01Cointelegraph will update the article upon receiving further comment from Rapid7 analysts regarding target filtering, hardware wallet spoofing, and self-custody vulnerabilities.
CME Headlines
  • Product Modification Summary: Add Offset Eligibility to Bitcoin Futures, Micro Bitcoin Futures, Ether Futures and Micro Ether Futures Contracts — Effective September 14, 2026
    19 Aug · 9:15 PM
  • Amendments to CME Rule 855. (“Offsetting Positions for Different-Sized Contracts”) – Contracts Eligible for Offset Table to Include Bitcoin Futures, Micro Bitcoin Futures, Ether Futures and Micro Ether Futures Contracts
    19 Aug · 7:45 PM

How It Developed

Rapid7 unveiled Operation Asterix, a crypto phishing campaign targeting 885,000 phone numbers.
The campaign aimed to steal cryptocurrency investors' assets by redirecting them to fake wallet provider websites.
Attackers impersonated legitimate services like Crypto.com, Ledger, Trezor, and Exodus.
The largest dataset comprised 316,002 German mobile numbers, with other directories covering Hong Kong, the UK, US, and Canada.
Rapid7 reported a "hit rate" of approximately 13.6% for the campaign, matching 43,066 accounts to cryptocurrency users.
AI tools were identified as a significant component of the phishing campaign.
Phishing attacks accounted for $306 million of the crypto industry's $482 million losses in Q1.

Sources

T1
Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbersRapid7 unveiled a new cryptocurrency phishing campaign targeting 885,000 phone numbers, aiming to steal investors’ holdings by redirecting them to fake wallet provider websites.Cointelegraph

Related Stories

Crypto generated 1% of Webull's record $198M Q2 revenue
20 Aug · 11:16 AM
150+ Polymarket Wallets May Have Traded on US Military Secrets, Research Finds
20 Aug · 10:08 AM
SEC Proposes First Formal Crypto Rules for Token Fundraising
19 Aug · 2:36 PM
Bitcoin.com wallet integrates UAE-registered US dollar stablecoin USDU
19 Aug · 8:41 PM
Binance launches AI trading platform, placing user oversight at its core
20 Aug · 9:46 AM