Security company reveals "Operation Asterix": Large-scale cryptocurrency phishing and voice fraud
Cybersecurity company Rapid7 recently disclosed a large-scale cryptocurrency phishing and voice fraud campaign called "Operation Asterix". The activity attempts to steal the assets of crypto investors by impersonating well-known wallet brands and deceiving victims to download fake apps.
Rapid7 pointed out in a report released this week that the attacker obtained data covering approximately 885,000 phone numbers in multiple countries, then used the exchange account matching mechanism to target the target, and eventually placed thousands of linked Binance user accounts in the attack queue to carry out follow-up attacks.
Core Discovery
Rapid7 estimates that the campaign was based on a dataset of approximately 885,000 phone numbers, with the largest file containing 316,002 German mobile phone numbers.
Rapid7 found evidence that the attacker matched 5,576 accounts associated with Binance users and had been "placed on the attack queue."
Among the verified exchange-linked targets, Rapid7 calculated that the approximate "hit rate" for the German dataset was approximately 13.6%.
This activity uses impersonation to steal mnemonic words, including forged tips and contact methods that impersonate customer service.
Artifacts recovered by Rapid7 show that the attacker used automated tools, including artificial intelligence (AI), to support multiple aspects of the activity.
How Operation Asterix targets cryptocurrency users
Rapid7's analysis, written by Anna Sirokova and Jan Recinsky, describes how attackers evolved from obtaining contact data to attempting to steal credentials and mnemonics. The core tactic is to guide victims to access fake apps designed to impersonate wallets and wallet ecosystems.
According to reports, the false inducement information explicitly mentioned well-known self-managed wallet brands including Ledger, Trezor and Exodus. The attacker tried to extract mnemonic words by enticing the victim to use counterfeit software and cooperating with "customer service" interaction.
Rapid7 also pointed out that contact methods include fake emails and phone inquiries, which is in line with the phishing plus voice fraud workflow. In other words, the activity is not limited to a single deception method, but uses multiple contact channels to increase the likelihood that victims will be deceived.
Targeting screening matches exchange accounts
An important part of Rapid7's findings was the apparent use of targeting screening mechanisms by attackers. The report showed that the attacker matched 43,066 accounts associated with cryptocurrency users with exchange accounts, and then verified it against a large data set of more than 316,000 German phone numbers. Based on this, Rapid7 calculated that the "hit rate" for the German dataset was approximately 13.6%.
Rapid7's findings further indicate that the activity includes a check tool for the Kraken Exchange to batch verify that phone numbers are associated with accounts on the exchange. This means that the attacker does not blindly send a contact list, but first confirms that a specific number corresponds to an identity registered with the exchange before escalating the attack.
Regarding Binance, Rapid7 said the activity identified and locked 5,576 accounts for attacks. The report describes this as a direct result of matching efforts based on a larger data set.
Stealing mnemonics through wallet counterfeiting
The artifact recovered by Rapid7 points to a strategy that directly attacks the vulnerability of self-managed wallets: combining wallet branding with users 'trust in "official" customer service channels. Rapid7 said victims were directed to fake apps imitating Ledger, Trezor and Exodus with the purpose of stealing mnemonic words.
This is crucial because mnemonics remain the highest value target in many cryptocurrency theft attempts. Once an attacker obtains a mnemonic word, he often can access the relevant wallet without bypassing complex encryption techniques, making social engineering a particularly effective attack route in practice.
Rapid7 's report also pointed out that the activity uses AI tools as an important operational tool. While the disclosure does not provide specific steps on how AI will be applied, it is in line with a broader trend: attackers are increasingly relying on automation to scale up personalization, message creation and workflow management.
Why fits a broader pattern of cryptocurrency fraud
"Operation Asterix" takes place against the backdrop of ongoing phishing and social engineering attacks in the field. Blockchain security company Hacken reported that of the $482 million lost in the first quarter of this year, phishing and social engineering fraud accounted for $306 million, according to data from Hacken cited by Rapid7.
This concentrated trend highlights the persistent asymmetry in the cryptocurrency security landscape: many of the most costly incidents are still attackers exploiting user behavior rather than breaking protocol rules. In this environment, matching phone number datasets and exchange accounts becomes particularly dangerous because they help scammers find potential victims through direct, targeted contact.
The tactics described in the Rapid7 report are also similar to previous industry incidents: it was previously reported that Trezor suffered a data breach in early August due to shipper ShipMonk, involving approximately 14,000 users; In July, an investor lost nearly US$1 million by signing a malicious phishing token approval transaction on Ethereum; in November 2023, a fake Ledger Live app incident appeared in the Microsoft Store, resulting in the theft of US$588,000 in 38 transactions.
Previous online reports also highlighted how scammers use mainstream platforms to distribute false tips; there have been cases where malicious ads placed through Google that impersonate Uniswap have resulted in losses of more than $400,000.
Follow-up concerns
The disclosure of Rapid7 may raise a new round of attention into how attackers combine contact data targeting, wallet branding, and automated tools. Investors and developers should be wary of subsequent signs, such as new fake wallet app deployments and continued exchange-related targeting, while the industry needs to work hard to reduce the human negligence on which scammers rely.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH