Cybersecurity firm Rapid7 has disclosed a large cryptocurrency phishing operation that it calls Operation Asterix, saying the campaign targeted about 885,000 phone numbers in several countries and regions. According to the firm, the attackers tried to steal digital assets by steering victims to fake websites and counterfeit applications that appeared to belong to well-known wallet and crypto service providers.
Rapid7 said the operation also involved fraudulent support-style outreach, including emails and phone contact designed to make targets hand over sensitive wallet information. The company described artificial intelligence tools as a significant part of the campaign and said roughly 13% of the targeted accounts were hit.
Large contact lists and Binance-linked matches
Rapid7 said the campaign drew on multiple datasets covering different markets. The biggest single list contained 316,002 German mobile phone numbers, while other lists related to Hong Kong, Bulgaria, the United Kingdom, the United States, Canadian fintech firms and Ledger-associated data.
Within the broader operation, Rapid7 said 5,576 accounts were matched to users of the crypto exchange Binance. The report did not frame that figure as proof of successful theft, but as part of the scope of the targeting activity uncovered during the investigation.
Impersonation of wallet brands and crypto firms
The phishing effort relied on brand impersonation across several parts of the crypto ecosystem. Rapid7 said fake emails were sent in the name of Crypto.com, while victims were also pushed toward counterfeit apps made to resemble products from Ledger, Trezor and Exodus.
The attackers also used bogus support messages and phone inquiries, a tactic meant to give the operation a customer-service appearance. By blending fake websites, sham applications and direct contact, the campaign appears to have been structured to build trust long enough to convince victims to reveal information that could be used to access their holdings.
Social engineering rather than software exploits
Rapid7 said Operation Asterix reflects a familiar pattern in crypto crime: attackers often focus on people instead of breaking software. Rather than exploiting technical flaws, phishing campaigns typically try to persuade users to disclose seed phrases or other highly sensitive credentials.
That approach remains one of the industry’s persistent risks because it depends on deception and urgency instead of a vulnerability in code. In this case, Rapid7 said AI tools played a meaningful role in the campaign, underscoring how phishing operations can scale and tailor messages while continuing to rely on social engineering.
What is confirmed so far
The findings presented so far establish the campaign’s reported scale, the brands impersonated and the geographies represented in the leaked or compiled contact lists described by Rapid7. The firm said about 13% of the targeted accounts were hit, but the source material does not provide a breakdown of losses or a country-by-country impact assessment.
For now, the clearest confirmed takeaway is that the operation used broad contact databases, exchange-linked account matching and fake wallet-provider infrastructure to pursue crypto users across multiple jurisdictions. Further detail, if any, would depend on additional disclosures from Rapid7 or affected companies.
Source: cointelegraph.com