Security Researchers Expose Massive Crypto Phishing Scheme Compromising Nearly 900,000 Mobile Users

Security Researchers Expose Massive Crypto Phishing Scheme Compromising Nearly 900,000 Mobile Users

Security research company Rapid7 has disclosed details of a sophisticated cryptocurrency phishing operation that compromised 885,000 phone numbers, designed to drain digital assets by directing victims to fraudulent crypto wallet platforms.

Security research organization Rapid7 has exposed details of a sophisticated cryptocurrency phishing operation dubbed Operation Asterix, which set its sights on approximately 885,000 mobile phone numbers spanning multiple nations in an effort to drain cryptocurrency holdings from digital asset investors.

The malicious phishing operation resulted in 5,576 user accounts being identified and matched to individuals holding accounts on cryptocurrency platform Binance, all of which were prepared for exploitation, while retrieved data logs additionally revealed fraudulent communications masquerading as official Crypto.com correspondence, as detailed in a Monday disclosure from Rapid7.

Among the 885,000 compromised phone numbers, the most substantial data collection contained 316,002 mobile numbers originating from Germany, alongside separate directories encompassing Hong Kong, Bulgaria, the United Kingdom, the United States, Canadian financial technology enterprises, and supplementary lists associated with Ledger.

Social engineering tactics and phishing assaults were responsible for the bulk of cryptocurrency sector financial damages during the year's opening quarter, representing $306 million of the aggregate $482 million in losses, as reported by blockchain security firm Hacken.

Within the Asterix phishing operation outlined by Rapid7 security researchers Anna Sirokova and Jan Recinsky, threat actors directed targets to counterfeit applications mimicking Ledger, Trezor, and Exodus platforms, with the objective of obtaining victims' recovery seed phrases. The perpetrators initiated contact with potential victims via fraudulent customer support electronic mail and telephone communications.

Operation Asterix kill chain diagram
The Operation Asterix attack chain showing stages from initial acquisition through final data exfiltration. Source: Rapid7.

Cointelegraph has reached out to the security analysts for additional commentary regarding their discoveries concerning victim filtering methodologies, hardware wallet impersonation tactics, and security weaknesses in self-custody solutions. This article will be amended upon receiving their response.

Previously in August, cryptocurrency wallet company Trezor disclosed a security incident involving the exposure of personally identifiable information impacting approximately 14,000 customers through a compromise at its logistics partner, ShipMonk.

During July, a digital currency holder suffered losses approaching $1 million following the execution of a malicious phishing token authorization transaction on the Ethereum blockchain.

In November 2023, a counterfeit Ledger Live application distributed through the Microsoft Store led to the misappropriation of $588,000 spread across 38 separate transactions.

Asterix phishing campaign boasts 13% "hit rate"

Threat actors successfully matched 43,066 user accounts to cryptocurrency holders possessing exchange platform accounts, confirmed from the broader German database exceeding 316,000 mobile numbers, indicating that the operation achieved a "hit rate" of roughly 13.6%, as documented by Rapid7.

The analysis additionally uncovered a verification tool designed for Kraken, which was engineered to perform mass validation of phone numbers against user accounts registered with the digital currency exchange. The cybersecurity organization noted that the retrieved evidence demonstrated that artificial intelligence technologies played a substantial role throughout the phishing operation.

Phishing exploits represent an enduring challenge for the cryptocurrency sector, given that they allow malicious actors to take advantage of human psychology and behavior instead of exploiting vulnerabilities in protocol source code.

On May 25, blockchain intelligence analyst "b-block" issued an alert that fraudsters leveraged Google's advertising platform to distribute harmful phishing advertisements impersonating the decentralized trading platform Uniswap, allegedly draining in excess of $400,000 from unsuspecting victims.

Prominent cryptocurrency industry leaders, including Binance co-founder Changpeng Zhao, have historically advocated for enhanced wallet security protocols to prevent phishing exploits, following an incident where an investor was defrauded of $50 million through an address poisoning scheme in December 2025.