Cybersecurity agency Rapid7 unveiled a brand new cryptocurrency phishing marketing campaign referred to as Operation Asterix, focusing on roughly 885,000 cellphone numbers from a number of international locations to steal cryptocurrency buyers’ belongings.
The phishing marketing campaign led to 5,576 accounts matched to customers on crypto change Binance, which have been queued for assault, whereas the recovered logs additionally confirmed faux emails impersonating Crypto.com, in keeping with a Monday report by Rapid7.
Of the 885,000 cellphone numbers, the most important file included 316,002 German cell numbers, with extra directories masking Hong Kong, Bulgaria, the UK, the US, Canadian fintech firms and extra Ledger-related lists.
Phishing assaults and social engineering scams drove nearly all of the crypto business’s losses within the first quarter of the 12 months, accounting for $306 million out of the whole $482 million misplaced, in keeping with blockchain safety firm Hacken.
As a part of the Asterix phishing marketing campaign detailed by Rapid7 analysts Anna Sirokova and Jan Recinsky, attackers drove victims to faux apps impersonating Ledger, Trezor, and Exodus, searching for to steal their seed phrases. Attackers reached out to victims via faux assist emails and cellphone inquiries.

Operation Aseterix kill chain from acquisition to exfiltration. Supply: Rapid7.
Cointelegraph has contacted the analysts for additional touch upon what they discovered concerning goal filtering, {hardware} pockets spoofing and self-custody vulnerabilities. We’ll replace this text after they reply.
Earlier in August, pockets supplier Trezor reported a breach of private knowledge affecting about 14,000 customers via its transport supplier, ShipMonk.
In July, a crypto investor misplaced practically $1 million after signing a malicious phishing token approval transaction on Ethereum.
In November 2023, a faux Ledger Dwell app on the Microsoft Retailer resulted within the theft of $588,000 throughout 38 transactions.
Associated: DefiLlama delayed cell launch over phishing apps on Apple Retailer, founder says
Asterix phishing marketing campaign boasts 13% “hit price”
Attackers matched 43,066 accounts to cryptocurrency customers with change accounts, validated from the bigger German dataset of over 316,000 cellphone numbers, that means that the marketing campaign has a “hit price” of roughly 13.6%, in keeping with Rapid7.
The report additionally recognized a checker for Kraken, which sought to bulk-validate cellphone numbers in opposition to accounts from the cryptocurrency change. The cybersecurity firm stated that the recovered artifacts confirmed that synthetic intelligence instruments have been used as a major a part of the phishing marketing campaign.
Phishing assaults are a long-standing headwind for the crypto business, as they allow attackers to use human conduct fairly than the code of a protocol.
On Could 25, onchain analyst “b-block” warned that scammers used Google to deploy malicious phishing adverts impersonating decentralized change Uniswap, reportedly stealing greater than $400,000 from victims.
Main crypto business figures, together with Binance co-founder Changpeng Zhao, have beforehand known as for higher pockets safety measures to keep away from phishing scams, after an investor misplaced $50 million in an deal with poisoning rip-off in December 2025.
Journal: How a ‘Fallacious Quantity’ message changed into a $3.4M crypto rip-off
