Cybersecurity firm exposes large-scale crypto phishing campaign targeting 885,000 phone numbers
Phishing campaign targets nearly 900,000 phone numbers in crypto scam
Cybersecurity firm Rapid7 has uncovered a phishing campaign called Operation Asterix, which targets nearly 885,000 phone numbers to steal cryptocurrency from investors. The campaign tricks users into visiting fake websites that mimic popular wallet providers, where attackers attempt to steal seed phrases—secret words used to access crypto wallets.
The campaign has already matched 5,576 accounts to users on the crypto exchange Binance, marking them for potential attacks. Attackers also sent fake emails pretending to be from Crypto.com, a well-known crypto trading platform.
Key details of the phishing operation
- Targets 885,000 phone numbers across Germany, Hong Kong, Bulgaria, the UK, the US, and Canada.
- Largest target group: 316,002 German mobile numbers.
- Fake apps impersonate Ledger, Trezor, and Exodus wallets to steal seed phrases.
- Attackers contact victims through fake support emails and phone calls.
- 13.6% of targeted German numbers matched to crypto exchange accounts.
- Artificial intelligence tools were used in the campaign.
How the scam works
Operation Asterix uses fake apps that look like real wallet providers such as Ledger, Trezor, and Exodus. These apps ask users to enter their seed phrases, which attackers then steal to gain access to the victims' crypto funds. The campaign also includes fake support emails and phone calls to trick users into sharing sensitive information.
Rapid7 found that attackers used a tool to check if phone numbers were linked to accounts on the Kraken crypto exchange. This helped them focus on users who likely owned cryptocurrency.
What is confirmed
- Rapid7 identified a phishing campaign targeting 885,000 phone numbers.
- 5,576 Binance accounts were matched for potential attacks.
- Fake emails impersonating Crypto.com were part of the campaign.
- Attackers used fake apps for Ledger, Trezor, and Exodus wallets.
- 316,002 German mobile numbers were the largest target group.
- 13.6% of German numbers matched to crypto exchange accounts.
- AI tools were used in the campaign.
What is still unclear
- No response yet from Rapid7 analysts on additional details about target filtering or hardware wallet vulnerabilities.
- It is not confirmed how many victims have already lost funds due to this campaign.
Why this matters for crypto users
Phishing scams like Operation Asterix are a major threat to crypto investors. Unlike hacking attacks that exploit software flaws, phishing relies on tricking people into sharing sensitive information. Seed phrases are especially valuable because they give full access to a crypto wallet. Users who fall for these scams can lose all their funds with no way to recover them.
This campaign also shows how attackers use AI and large datasets to improve their success rates. By targeting phone numbers linked to crypto exchange accounts, they increase the chances of stealing valuable assets.
Recent crypto phishing incidents
- In August 2026, Trezor reported a data breach affecting 14,000 users through its shipping provider.
- In July 2026, a crypto investor lost nearly $1 million after signing a malicious phishing token approval on Ethereum.
- In November 2023, a fake Ledger Live app on the Microsoft Store stole $588,000 from victims.