Operation Asterix Exposed: How an AI-Powered Phishing Syndicate Targeted 885,000 Crypto Holders
A massive cybercrime infrastructure dubbed Operation Asterix has been exposed by cybersecurity firm Rapid7. The campaign compiled a database of nearly 885,000 phone numbers across 54 countries to launch high-precision social engineering, voice-phishing (vishing), and counterfeit application deployments against cryptocurrency investors. Rather than relying on traditional broad-spectrum spam, the operation integrated automated account verification tools and generative AI coding assistants to systematically harvest private recovery seed phrases from high-value target accounts.
Please Register !
The Scale and Reach of Operation Asterix
Please Register !
Threat intelligence analysts at Rapid7 discovered an exposed directory hosting command-and-control (C2) artifacts from the syndicate. Their investigation revealed an extensive target database containing 885,000 mobile numbers. The largest localized file comprised 316,002 German phone numbers, with supplementary directories covering targets in Hong Kong, Bulgaria, the United Kingdom, the United States, Canadian fintech services, and specialized lists of hardware wallet owners.
Please Register !
Precision Targeting and the 13.6% "Hit Rate"
Please Register !
What sets Operation Asterix apart from typical phishing campaigns is its automated validation pipeline. Scammers avoided spraying messages blindly; instead, they processed leaked numbers through account-checking scripts to verify if they were linked to major crypto exchanges like Binance and Kraken.
Please Register !
An additional 5,576 accounts were confirmed as Binance users and queued for immediate attack. Recovered C2 logs also revealed malicious spoofed emails pretending to originate from Crypto.com. Once an exchange match was confirmed, scammers enriched the lead profile with personal victim data, enabling call handlers to execute convincingly detailed voice-phishing (vishing) calls.
Please Register !
AI Assistants & Telephony Infrastructure
Please Register !
Rapid7 researchers Anna Sirokova and Jan Recinsky discovered that generative AI tools played a core role throughout the development of the campaign. Shell command histories and prompt logs indicated the operators used AI assistants like GitHub Copilot and Claude Code to rapidly build trojanized Electron applications, obfuscate payload scripts, and configure C2 servers.
When certain AI platforms resisted code obfuscation requests, the attackers attempted to bypass safety guardrails by submitting custom jailbreak prompts to alternative models like Kimi. To manage their call networks, the operators deployed the open-source telephony framework Asterisk (which inspired the operation's codename).
Please Register !
Please Register !
Counterfeit Wallet Apps: Spoofing Ledger, Trezor, and Exodus
Please Register !
The ultimate goal of Operation Asterix was to trick victims into installing fake versions of popular wallet software. Through direct phone calls and phishing emails, targets were instructed to download malicious clones of Trezor Suite, Ledger Live, and Exodus.
These fake apps were visual carbon copies of authentic software. When launched, they requested the user's 12- or 24-word recovery seed phrase under the guise of mandatory security checks or firmware updates. The moment a seed phrase was entered, it was transmitted to attacker-controlled Telegram bots, handing scammers full control of the victim's private key.
Please Register !
Industry Context: Social Engineering Dominates Crypto Losses
Please Register !
Operation Asterix reflects a broader structural shift in Web3 cybercrime: attackers are increasingly exploiting human trust rather than protocol smart contracts. According to quarterly research by security firm Hacken Security, phishing and social engineering caused $306 million in losses out of the $482 million total lost across the crypto market in Q1.
Recent high-profile security incidents highlight the scale of this problem:
-
Trezor Data Leak (August): Trezor confirmed that personal contact information for ~14,000 customers was compromised due to a security breach at its logistics partner, ShipMonk.
-
Ethereum Approval Exploit (July): A crypto investor lost nearly $1 million after inadvertently signing a malicious token approval transaction on Ethereum.
-
Fake Microsoft Store App (November): A fake Ledger Live application uploaded to the official Microsoft Store stole $588,000 across 38 fraudulent transactions.
-
Uniswap Google Ads Scam (May 25): On-chain analyst b-block on X issued an urgent warning after sponsored Google search ads impersonated the decentralized exchange Uniswap, stealing over $400,000 from unsuspecting users.
-
Address Poisoning Warnings: Prominent Web3 figures, including Binance co-founder Changpeng Zhao (CZ), have repeatedly warned about address poisoning schemes after an investor lost $50 million in a single poisoning scam.
Please Register !
Actionable Defense Strategies for Investors
Please Register !
To safeguard your digital assets against Operation Asterix and evolving vishing campaigns, follow these essential security rules:
-
The Zero-Seed-Phrase Rule: Hardware wallet providers (Ledger, Trezor) will NEVER ask you to enter your recovery seed phrase into a computer or phone app. Recovery phrases must only be entered directly into the physical hardware device itself.
-
Ignore Direct Phone Support: Crypto exchanges and wallet vendors do not place inbound support calls regarding account security. If anyone calls claiming suspicious wallet activity, hang up immediately.
-
Verify App Source URLs: Download management software strictly from confirmed, bookmarked vendor websites. Avoid clicking top-sponsored search results or links in SMS messages.
-
Audit Smart Contract Permissions: Frequently inspect and revoke active wallet approvals using tools like Revoke.cash.

Recommended Comments
There are no comments to display.
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.