Rapid7 Uncovers ASTERIX Crypto Theft Campaign Using Voice Phishing, Fake Wallets
Cryptocurrency wallet recovery phrases effectively confer control over the assets they protect, making them a high-value target for criminals because blockchain transfers are typically difficult to reverse. Rapid7’s disclosure of Operation ASTERIX shows how attackers are combining phishing emails, persuasive phone calls and counterfeit wallet software into a targeted social-engineering chain aimed at cryptocurrency users.
Rapid7 said the attackers first approached targets by email and then used voice phishing to build credibility, persuading victims to install a trojanized fake wallet designed to capture their recovery phrases. Investigators also found that the operators used GitHub Copilot and Claude Code to help manage target lists, scripts and configuration files, illustrating how generative AI tools are being incorporated into the operational workflow of cryptocurrency scams.
All Coverage
1 original reportsThe Backstory
The history behind this eventRapid7 Uncovers Crypto Phishing Campaign Targeting 885,000 Phone Numbers
Cryptocurrency transfers are generally irreversible, making stolen credentials and wallet recovery phrases especially valuable to criminals. Rapid7’s investigation into Operation ASTERIX shows how phishing has evolved from isolated fake pages into an industrialized fraud pipeline combining leaked phone lists, account-validation tools, impersonation calls and counterfeit wallet software. By posing as trusted brands including Binance, Crypto.com and Ledger, operators can identify crypto holders, enrich their profiles and pressure them into surrendering access to assets that may be difficult to recover.
Rapid7 researchers Anna Širokova and Jan Recinsky disclosed the campaign on Aug. 17, 2026, after finding an exposed server containing roughly 885,000 phone numbers, phishing panels, voice-dialing scripts and malicious applications. In one German dataset, the operators validated 43,066 Crypto.com accounts from 316,002 numbers, a hit rate of about 13.6%. The infrastructure also supported lures impersonating Binance and Ledger and sought login details or recovery phrases. Rapid7 did not report a confirmed victim count or dollar loss, leaving the campaign’s financial impact unknown.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →