Key facts
- Cybersecurity firm Rapid7 identified a cryptocurrency phishing campaign named Operation Asterix.
- The campaign targeted 885,000 phone numbers across several countries, including Germany, Hong Kong, the UK, and the US.
- Attackers used fake websites and emails impersonating legitimate wallet providers and exchanges like Ledger, Trezor, Exodus, and Binance.
- The campaign achieved an estimated 13.6% "hit rate", matching over 43,000 accounts to cryptocurrency users.
- Artificial intelligence tools were utilized in the phishing campaign.
Cybersecurity firm Rapid7 has detailed a large-scale cryptocurrency phishing campaign, dubbed Operation Asterix, which targeted approximately 885,000 phone numbers across multiple countries. The campaign's objective was to steal assets from cryptocurrency investors by luring them to fraudulent websites that mimicked legitimate wallet providers and exchanges.
According to Rapid7's report, the attackers employed fake emails and phone inquiries to impersonate services such as Crypto.com, Ledger, Trezor, and Exodus. The recovered logs indicated that 5,576 accounts linked to users on the crypto exchange Binance were identified as targets. The largest dataset of phone numbers included 316,002 German mobile numbers, with additional directories covering Hong Kong, Bulgaria, the UK, the US, and Canadian fintech companies, alongside Ledger-related lists.
Rapid7 analysts Anna Sirokova and Jan Recinsky highlighted that the campaign achieved a "hit rate" of approximately 13.6%, successfully matching 43,066 accounts to cryptocurrency users from the German dataset alone. The recovered artifacts also revealed a checker for Kraken, suggesting an attempt to validate phone numbers against accounts on that exchange.
Phishing attacks and social engineering scams have been a significant driver of losses in the cryptocurrency industry. In the first quarter of the year, these types of attacks accounted for $306 million out of a total of $482 million lost, according to blockchain security company Hacken. The report from Rapid7 also noted the use of artificial intelligence tools as a substantial part of the phishing campaign.
This campaign follows other notable incidents, including a data breach affecting about 14,000 Trezor users via its shipping provider, ShipMonk, and a crypto investor losing nearly $1 million due to a malicious phishing token approval transaction on Ethereum. In November 2023, a fake Ledger Live app on the Microsoft Store led to the theft of $588,000 across 38 transactions.
Phishing remains a persistent challenge for the crypto industry, as it exploits human behavior rather than protocol vulnerabilities. Earlier in May, scammers reportedly used malicious phishing ads impersonating Uniswap to steal over $400,000. Industry figures like Binance co-founder Changpeng Zhao have previously urged for enhanced wallet security measures to combat such scams.