Cybersecurity firm Rapid7 has uncovered a large-scale cryptocurrency phishing operation dubbed Operation Asterix, involving a database of roughly 885,000 phone numbers across multiple countries.
The campaign appears designed to identify cryptocurrency users and lure them toward fraudulent wallet and exchange websites or applications in an effort to steal sensitive credentials, including seed phrases and other information that can provide access to digital assets.
Operation Asterix Targets Crypto Users
According to Rapid7 researchers, the campaign involved extensive lists of phone numbers from Germany, Hong Kong, Bulgaria, the United Kingdom, the United States and Canada, along with lists associated with cryptocurrency hardware-wallet users.
The largest dataset contained approximately 316,000 German mobile numbers.
Rapid7 also identified 5,576 Binance accounts that had been matched to phone numbers and placed in a queue for potential attacks. Recovered campaign material also included fake emails designed to impersonate cryptocurrency platforms such as Crypto.com.
The attackers reportedly used a combination of phishing emails, fraudulent customer-support communications and phone calls to direct victims toward malicious applications and websites.
Fake Ledger, Trezor and Exodus Apps
A key element of the operation involved impersonating major cryptocurrency wallet providers, including Ledger, Trezor and Exodus.
Victims were reportedly encouraged to interact with fake applications or websites that appeared legitimate. The ultimate objective was to convince users to enter their seed phrases, which could then be used by attackers to gain control of their cryptocurrency wallets.
The campaign highlights a major vulnerability in self-custody: unlike traditional financial accounts, a stolen seed phrase can provide direct access to a wallet’s assets without requiring further approval from a bank or intermediary.
Rapid7 researchers also discovered tools designed to check whether phone numbers were associated with accounts at major cryptocurrency exchanges. A separate checker reportedly targeted Kraken users.
Attackers Used AI Tools
Rapid7 said recovered evidence indicated that artificial intelligence tools played a significant role in the campaign.
The use of AI can make phishing operations more scalable by helping attackers create convincing communications, automate targeting and personalize messages for potential victims.
That makes traditional warning signs such as poor grammar, awkward wording or obvious spelling mistakes less reliable than they once were.
The broader crypto industry has already experienced significant losses from social engineering and phishing attacks.
According to blockchain security firm Hacken, phishing and social-engineering attacks accounted for approximately $306 million of the $482 million lost by the crypto industry during the first quarter of the year.
Campaign Reportedly Achieved a 13.6% Hit Rate
Rapid7 found that attackers were able to match approximately 43,066 cryptocurrency-related accounts against the German phone-number database containing more than 316,000 numbers.
That represents an estimated 13.6% hit rate, suggesting the attackers had access to substantial information that could help identify people likely to hold cryptocurrency accounts.
The ability to filter potential victims before launching phishing attempts could make the operation significantly more efficient than sending generic messages to random phone numbers.
The discovery of exchange-account checkers further suggests that the campaign was designed around identifying high-value cryptocurrency targets.
Phishing Remains a Major Crypto Security Threat
Operation Asterix is the latest example of how criminals are increasingly targeting users rather than attempting to exploit vulnerabilities directly in blockchain protocols.
Recent incidents have included fraudulent wallet applications, malicious token approvals and fake advertisements designed to redirect users to counterfeit cryptocurrency services.
Earlier in August, Trezor disclosed that personal information belonging to approximately 14,000 customers had been exposed through a breach involving its shipping provider.
In another incident in July, a cryptocurrency investor reportedly lost nearly $1 million after signing a malicious token-approval transaction on Ethereum.
A fake Ledger Live application distributed through Microsoft’s app marketplace previously resulted in approximately $588,000 in cryptocurrency theft across 38 transactions.
Self-Custody Remains a Key Target
The campaign also underscores the risks surrounding hardware wallets and self-custody.
Hardware wallets can significantly reduce certain online security risks, but they cannot protect users who voluntarily disclose their seed phrases to fraudulent websites, applications or supposed customer-support representatives.
Attackers increasingly use impersonation to create a false sense of urgency, claiming that a wallet requires verification, an account has been compromised or a transaction must be canceled immediately.
Once a victim enters a seed phrase into a malicious interface, the attacker can potentially transfer the assets controlled by that wallet.
How Users Can Reduce the Risk
The discovery of Operation Asterix reinforces several basic security practices for cryptocurrency users:
- Never share a wallet seed phrase, even with someone claiming to be official customer support.
- Avoid clicking links received through unsolicited emails, text messages or phone calls.
- Download wallet applications only through verified official channels.
- Independently type the official website address rather than following links in messages.
- Treat unexpected account-security alerts with caution.
- Verify cryptocurrency addresses and transaction details before approving transactions.
- Remember that legitimate wallet providers generally do not need users to disclose their recovery phrases.
As AI makes fraudulent communications increasingly convincing, users may need to rely less on how legitimate a message looks and more on independent verification of the source and transaction.
Operation Asterix demonstrates how crypto phishing has evolved from simple fake websites into sophisticated, data-driven campaigns capable of identifying potential cryptocurrency users at scale. For investors, protecting the seed phrase remains one of the most important lines of defense against this growing category of attacks.

