
A phishing campaign doesn’t need to fool everyone. It just needs to fool enough people. That’s the uncomfortable math behind Operation Asterix, a crypto-targeting attack campaign that cybersecurity firm Rapid7 detailed in a new report, showing that attackers matched roughly 13.6% of their target list to real cryptocurrency exchange accounts. When your list has 885,000 phone numbers on it, that percentage adds up fast.
Rapid7 analysts Anna Sirokova and Jan Recinsky found that the campaign, which they named Operation Asterix, pulled together phone number directories from Germany, Hong Kong, Bulgaria, the UK, the US, and Canada. The largest single file contained 316,002 German mobile numbers. From that German dataset alone, attackers identified 43,066 accounts linked to active cryptocurrency users. Separately, 5,576 accounts were matched to Binance users and placed in a queue for targeting. The recovered data also showed fake emails impersonating Crypto.com, alongside a checker tool designed to bulk-validate phone numbers against Kraken accounts.
The attack chain followed a familiar but effective pattern. Victims were contacted through fake support emails and phone calls, then pushed toward counterfeit apps impersonating Ledger, Trezor, and Exodus. The goal was seed phrase theft. If an attacker gets your seed phrase, they own your wallet. There’s no customer support line to call, no charge reversal, no recovery. This is why hardware wallet spoofing is particularly dangerous: it targets users who already took steps to secure their funds and may trust a prompt that appears to come from their own device’s software.
What makes Operation Asterix stand out from older phishing campaigns is the reported use of AI tools as a core part of the operation. Rapid7 said recovered artifacts showed AI was used at multiple points in the campaign, though the specific applications weren’t fully detailed in the public report. This fits a broader pattern security researchers have been warning about: AI is lowering the cost and raising the quality of social engineering attacks. Fake emails are harder to spot. Fake phone support sounds more convincing. The volume of attacks that can be run simultaneously goes up.
The timing of this report is worth considering. This year, phishing and social engineering attacks accounted for $306 million of the $482 million lost across the crypto industry in the first quarter alone, according to blockchain security firm Hacken. That’s nearly two-thirds of total losses coming not from protocol exploits or smart contract bugs, but from humans being tricked. And the incidents keep coming. In July, one investor lost close to $1 million after signing a malicious token approval transaction on Ethereum. In November 2023, a fake Ledger Live app on the Microsoft Store drained $588,000. Earlier this month, Trezor confirmed a data breach affecting around 14,000 users through its shipping provider, ShipMonk.
The personal data exposed in breaches like that one feeds directly into campaigns like Operation Asterix. Attackers don’t need to guess who owns crypto. They can buy or steal lists, cross-reference them with leaked exchange data, and filter down to high-probability targets. The 885,000-number dataset isn’t random. It’s curated.
For users, the practical takeaways are specific:
- Never enter your seed phrase into any app or website, regardless of how official it looks
- Treat any unsolicited support contact, by email or phone, as suspicious by default
- Download wallet software only from official, verified sources and check URLs carefully
- Be aware that your phone number may already be on a list like this one
But individual caution only goes so far when the attacks are this systematic. Binance co-founder Changpeng Zhao has previously pushed for stronger wallet security standards industry-wide, and that conversation isn’t going away. So far, the industry’s response has been slower than the attackers’ adaptation. Operation Asterix is a reminder that the gap is not closing on its own.