Skip to content

Independent intelligence on digital money in motion

Monday, August 24, 2026

Latest SBI Leads Fasset Series C as Stablecoin Banking Plans Expand
Security

Rapid7 Finds Crypto Phishing Pipeline Built Around 885,000 Phone Numbers

Operation ASTERIX combined account checks, fake support messages, calls and counterfeit wallet apps to target cryptocurrency users.

Cybersecurity researchers have uncovered a cryptocurrency phishing operation that combined a database of about 885,000 phone numbers with account-validation tools, fake support messages, voice calls and counterfeit wallet applications.

Rapid7 said the exposed infrastructure showed how the operation, which it tracks as Operation ASTERIX, narrowed broad contact lists into cryptocurrency users and then tried to obtain wallet recovery phrases. The researchers found artifacts for applications impersonating Ledger, Trezor and Exodus, as well as tooling for email phishing, automated calling and data exfiltration through Telegram.

The finding documents the design of a large fraud pipeline, not a confirmed loss total. Rapid7 said it did not recover call logs that would reconstruct every interaction, and its report did not quantify successful thefts or affected victims. The 885,000 figure describes phone numbers held on the exposed server rather than 885,000 proven compromises.

Account checks turned contact data into targeted leads

The largest recovered file contained 316,002 German mobile numbers. Rapid7 said account-validation tooling matched 43,066 of those numbers to cryptocurrency exchange accounts, a rate of about 13.6%. Other directories referenced Hong Kong, Bulgaria, the United Kingdom, the United States, Canadian fintech companies and Ledger-related lists spanning 54 countries.

A separate operator panel displayed 5,576 validated cryptocurrency targets queued for attack. Those records indicate targeting intent and preparation, but they do not establish that every person was contacted or lost funds.

The operation sought to make its outreach more convincing by linking channels. Rapid7 found phishing panels that generated fake support cases and verification codes, which could then be referenced in phone calls. That coordination can make a fraudulent contact look more credible because the caller appears to know details from an earlier message.

Counterfeit wallet software moved the attack beyond email

The recovered Trezor impersonation waited for a user to open the legitimate Trezor Suite before displaying a counterfeit interface. That interface requested a recovery phrase and optional passphrase, then sent the submitted data and the user’s public IP address to a Telegram bot, according to Rapid7.

Other recovered builds impersonated Ledger Live and Exodus. Rapid7 said one Ledger-themed Windows build could replace a copied cryptocurrency address with an attacker-controlled address, while the broader toolset also included hidden processes and persistence mechanisms. These findings describe capabilities found in the exposed files; they are not proof that each technique succeeded against a victim.

Rapid7 said much of the infrastructure was still being used or developed when exposed. The company reported the identified infrastructure and findings to relevant providers and authorities, including Apple’s security team.

What wallet and payment providers can take from the campaign

For wallet providers, exchanges and crypto payment companies, the operational risk begins before a transaction reaches a blockchain. The campaign used customer contact data and account discovery to select targets, then tried to convert trust created through support-style communications into control of wallet credentials.

That makes transaction monitoring only one layer of defense. Providers also need controls around account-enumeration endpoints, rate limits, customer-support authentication, domain and application impersonation, and rapid warning channels for customers. A recovery phrase entered into counterfeit software can give an attacker direct control of assets, leaving little opportunity for a provider to reverse the resulting transfer.

The exposed operation also shows why fraud teams should connect signals across channels. Repeated account lookups, unusual validation traffic, newly registered support domains, branded phishing emails and reports of unsolicited calls may look separate when reviewed in isolation. Linking them can reveal the preparation and social-engineering stages before a victim submits credentials or initiates a payment.

Rapid7 published indicators of compromise for the malicious infrastructure and applications. Providers can use those indicators as defensive inputs, while keeping the evidentiary boundary clear: the investigation establishes the pipeline’s scale and capabilities, but not a verified number of victims or financial losses.