LIVE
Loading prices…

Operation ASTERIX: Inside the Machine Hunting 885,000 Crypto Targets

Operation ASTERIX exposed an industrial-scale system for identifying crypto holders before targeting them with fake calls, emails and wallet software. Inside the AI-assisted machine built around 885,000 phone numbers and thousands of verified exchange users.

Operation ASTERIX: Inside the Machine Hunting 885,000 Crypto Targets

If you own crypto, you probably believe you can recognise an obvious scam. Operation ASTERIX was designed for people who believe exactly that.

The attack did not begin with a clumsy message from a stranger. It began quietly, with leaked data, verified exchange accounts and enough information to make the eventual lie feel disturbingly plausible. Before the phone ever rang, the criminals may already have known that you owned crypto, which platform you used and which wallet they needed to impersonate.

No blockchain was exploited. No encryption was cracked. No hardware wallet suddenly forgot how to protect its keys.

Instead, somebody built a machine for convincing people to surrender them.

Cybersecurity researchers at Rapid7 discovered an exposed web directory belonging to what they describe as Operation ASTERIX, a sprawling crypto fraud operation combining leaked phone-number databases, exchange-account validation, personalised phishing emails, convincing support calls and counterfeit wallet applications.

The exposed server contained approximately 885,000 phone numbers, but these should not be confused with 885,000 confirmed crypto users or victims. They were the raw material.

The operation’s real power came from what happened next.

From Random Numbers to Confirmed Crypto Targets

Attackers had developed automated tools that checked whether individual phone numbers were connected to accounts on cryptocurrency platforms.

One German dataset contained 316,002 mobile numbers. By abusing a Crypto.com account-verification endpoint, the operators reportedly matched 43,066 numbers to existing accounts, a hit rate of approximately 13.6 percent.

That transformed a pile of anonymous numbers into a list of probable crypto holders.

Rapid7 also found separate tooling for checking Kraken accounts, Ledger-related datasets divided across 54 countries and directories referring to users in the United Kingdom, United States and Canada. A Binance lead-management panel displayed 5,576 validated crypto targets queued for attack.

The operators were not simply spraying scam messages across the internet and hoping somebody responded. They were filtering, confirming and enriching their targets before making contact.

Names, email addresses, locations, exchange associations and other personal details could then be attached to the confirmed numbers.

A cold call becomes considerably more convincing when the caller already knows your name, location and which exchange you use.

The Anatomy of Manufactured Trust

Operation ASTERIX appears to have combined email phishing and voice phishing, commonly known as vishing, into one coordinated performance.

The victim could first receive a professionally branded email claiming that a security incident, withdrawal request or support case had been opened. The message included a case number or verification code.

A caller would then contact the victim pretending to represent the same company.

Because the caller knew the code contained in the email, the telephone conversation appeared to confirm that the email was genuine. Because the email appeared to predict the call, the call made the email feel genuine.

Each fake channel authenticated the other.

The operation used Asterisk, the open-source telephone platform from which Rapid7 derived the campaign’s name, alongside automated dialling scripts and commercial call-routing software.

The recovered logs suggest that the final calls were handled selectively rather than blasted indiscriminately. One phishing panel recorded 20 successful lead lookups and six emails over roughly two weeks.

Automation found the targets. Humans appear to have closed the sale.

Fake Wallets, Real Theft

The final stage was not a crude webpage covered in spelling mistakes.

Rapid7 recovered counterfeit versions of Trezor Suite, Ledger Live and Exodus built for macOS and Windows. Each attempted to preserve the illusion that the victim was interacting with legitimate wallet software.

The fake Trezor application was particularly aggressive.

On macOS, it could remain hidden while monitoring the device for the genuine Trezor Suite. When the victim opened the legitimate application, the malware terminated it and placed its counterfeit window in front of the user.

From the victim’s perspective, they had opened Trezor Suite themselves. What appeared on the screen looked like the application they expected to see.

The fake interface then requested a 12, 18, 20 or 24-word recovery phrase and an optional passphrase. After the first submission, it displayed a fake validation process followed by an error, encouraging the victim to enter the words again more carefully.

This was quality control for theft.

The completed phrase, passphrase and victim’s IP address were then transmitted through a Telegram bot. The victim was redirected to the genuine Trezor website afterwards, delaying the moment they realised anything was wrong.

The counterfeit Ledger Live build contained a separate clipboard hijacker capable of replacing copied cryptocurrency addresses with an attacker-controlled address. The Exodus version used a modified JavaScript file to retrieve its malicious payload after installation, helping the original installer appear clean.

The wallet had not failed.

The attackers had placed themselves between the owner and the wallet.

AI Joined the Production Line

Rapid7 also recovered evidence showing that the operator used GitHub Copilot and Claude Code throughout the campaign.

The tools were reportedly used to clean and format target databases, configure proxies, troubleshoot validation scripts, develop backend infrastructure, package Electron applications and modify malicious code.

When Claude resisted requests involving malware obfuscation, the operator switched to another model, Kimi, and attempted to defeat its safeguards using an elaborate jailbreak prompt.

Rapid7 found no conclusive evidence that the second model complied. The significance lies in the workflow.

The attacker treated AI restrictions as another technical obstacle to troubleshoot. One assistant was used until it refused, another provider was selected, and a bypass was attempted.

AI did not invent phishing, impersonation or seed-phrase theft. It reduced the time, manpower and specialist knowledge required to connect them into one functioning pipeline.

The Attack Surface Begins Before the Wallet

Crypto security is still obsessed with smart-contract audits, protocol exploits and cryptography. Operation ASTERIX demonstrates how attackers can simply walk around those defences.

The attack begins much earlier:

Who knows that you own cryptocurrency?

Who has your telephone number?

Which exchange can be connected to it?

Where did you purchase your hardware wallet?

Which customer, delivery or support databases have exposed your details?

According to Hacken’s Q1 2026 Security and Compliance Report, phishing and social engineering accounted for approximately $306 million of the $482.6 million stolen during the quarter. A single hardware-wallet social-engineering incident represented most of that figure, but the wider direction is unmistakable.

Attackers do not always need better exploits.

Sometimes they only need better information about the person holding the keys.

What Wallet Owners Should Do

Treat every unsolicited wallet-support call, text message or direct message as hostile, even when the caller knows accurate personal information.

Never enter a hardware-wallet recovery phrase into a website, support form or application downloaded through a link sent by somebody else. Navigate to official websites manually and obtain wallet software only through verified sources.

Ledger states that it will never contact customers by telephone or text message and will never request a recovery phrase. Trezor gives an equally simple warning: any request for your wallet backup, PIN, password or verification code is a scam. Exodus says its support team will never request a secret key, private key or remote access to your device.

Personal knowledge is not proof of identity. A caller knowing your name, exchange or recent purchase may simply mean your information was leaked somewhere else.

If a recovery phrase has already been entered into a suspicious application or website, treat it as permanently compromised. Create a completely new wallet using verified software and a newly generated recovery phrase, then move the assets before the attacker does.

CipherBot Take

Self-custody removes the custodian. It does not remove the need for judgement.

Operation ASTERIX industrialised the moment when fear overwhelms verification. A leaked number became a confirmed exchange account. The account became an enriched identity. The identity received an email. The email prepared the call. The call delivered the fake wallet. The fake wallet collected the keys.

Every stage was designed to make the next stage feel legitimate.

The most secure hardware wallet in the world cannot protect a recovery phrase deliberately handed to a convincing imitation.

They do not need to crack the wallet.

They need to convince you to open it.

Primary research: Rapid7 Labs, Operation ASTERIX.

---

CipherBot

Zero Trust Network · Intelligence Division · Truth · Strategy · Sovereignty

Discussion