Community Trust ScoreVerified
A massive crypto phishing operation just got exposed. Rapid7 researchers uncovered a campaign they’re calling Operation Asterix — and the numbers are ugly. Nearly 885,000 phone numbers. Thousands of exchange accounts pre-loaded for attack. Multiple countries. And fake wallet apps designed to drain everything.
The scale here is hard to ignore. Rapid7 analysts Anna Sirokova and Jan Recinsky found 5,576 Binance accounts already queued up and ready to be hit. The largest single batch of targeted numbers came from Germany — 316,002 mobile numbers, with a hit rate of 13.6% against that dataset alone. That’s not a small operation running out of someone’s basement. Alongside the German list, attackers had compiled directories covering Hong Kong, Bulgaria, the UK, the US, and Canadian fintech companies. There were also separate lists tied specifically to Ledger cryptocurrency wallet users. Crypto.com was being impersonated too, per the logs Rapid7 pulled.
The mechanics are pretty straightforward, and that’s kind of what makes it so dangerous.
Fake Apps, Seed Phrases, and a Kraken Checker Tool
Attackers built fake versions of Ledger, Trezor, and Exodus — three of the most trusted names in self-custody storage. Victims get approached through fake support emails or phone calls, and once they’re convinced they’re talking to a real company, they’re pushed toward these counterfeit apps. The apps do one thing: steal seed phrases. Hand over your seed phrase and your funds are gone, full stop. No recovery. No dispute process. Just gone.
But the operation didn’t stop at fake apps. Rapid7 also found a checker tool built specifically for Kraken. It validated phone numbers against actual exchange accounts — basically a way to confirm which numbers on the list belonged to real, active Kraken users before wasting time on them. That kind of tooling takes real effort to build. It’s not improvised.
Artificial intelligence played a role here too. The report flagged AI tools being used to automate parts of the attack — generating fake support emails at scale, bulk-validating datasets, streamlining the whole targeting process. It’s faster, it’s more precise, and it lets a small group of attackers punch way above their weight in terms of reach. Phishing campaigns across the crypto industry have been getting more sophisticated for a while now, and the AI angle is probably part of why.
A Pattern of Costly Incidents
Operation Asterix didn’t come out of nowhere. The crypto industry has been bleeding from phishing for years, and the losses keep stacking up.
Trezor disclosed a breach back in August involving 14,000 users’ data, tied to a compromise at logistics firm ShipMonk. In July, a single phishing token approval on Ethereum cost one investor nearly $1 million. And before that, a fake Ledger Live app that somehow made it onto the Microsoft Store resulted in $588,000 stolen across 38 separate transactions. Thirty-eight. That’s not a one-off — that’s a sustained operation running long enough to rack up nearly four dozen victims before anyone pulled it down.
There’s also the $400,000 taken through fake Uniswap ads — attackers impersonating a DeFi platform through paid placements, catching users who thought they were clicking on something legitimate. And following a $50 million loss tied to a scam, calls for stronger wallet security got louder across the industry. Unclear whether those calls have translated into meaningful changes yet.
The broader picture isn’t great. Phishing and social engineering scams accounted for $306 million out of $482 million in total sector losses in the first quarter, per blockchain security firm Hacken. That’s a big chunk. And it’s basically all preventable — seed phrases shouldn’t be entered anywhere, ever, except a hardware wallet you physically control. But attackers are good at manufacturing urgency, manufacturing trust, manufacturing the feeling that something is wrong and you need to act right now.
Fake Ledger. Fake Trezor. Fake Exodus. Fake support calls. Fake emails. The playbook hasn’t changed much — it’s just gotten faster and more targeted, and now it’s got AI doing some of the heavy lifting.
Cointelegraph reached out to Rapid7 analysts for more details on the campaign’s target filtering and specific vulnerabilities. No response yet at time of publication.
The German dataset’s 13.6% hit rate — meaning roughly 1 in 7 numbers belonged to a verifiable crypto user — is probably the most telling number in the whole report.
Frequently Asked Questions
What is Operation Asterix and who discovered it?
Operation Asterix is a large-scale cryptocurrency phishing campaign targeting 885,000 phone numbers across multiple countries, uncovered by Rapid7 analysts Anna Sirokova and Jan Recinsky.
How many Binance accounts were identified as targets in Operation Asterix?
Rapid7 found 5,576 Binance accounts pre-identified for attack, with the German phone number dataset showing a 13.6% hit rate against exchange accounts.
Why It Matters
The exposure of Operation Asterix highlights the ongoing vulnerability of the cryptocurrency ecosystem to phishing attacks, which can undermine user trust and deter potential investors. With nearly 885,000 phone numbers involved, this incident underscores the scale of the threat facing major platforms like Binance, Ledger, and Trezor, potentially impacting user engagement and market stability. As malicious actors continue to adapt and innovate, the need for robust security measures becomes increasingly critical for both users and exchanges in maintaining the integrity of the crypto market.





