Crypto Scam News: Operation ASTERIX Exposes Fake Wallet Trap

20-Aug-2026 CoinGabbar

Crypto Scam News: Operation ASTERIX Exposes New Fraud Tactics

In the latest crypto scam news, cybersecurity firm Rapid7 has uncovered a large-scale fraud operation, tracked as Operation ASTERIX, that combined phishing emails, phone scams, and fake wallet apps to steal cryptocurrency recovery phrases from unsuspecting users. 

Information Cover by WuBlock

Source: Information Cover by WuBlock

Researchers found an exposed web directory on the operator's own server, which accidentally revealed almost every tool behind the scam—giving Rapid7 an unusually clear look at how the operation actually worked.

Source: Rapid7 Labs

Operation ASTERIX At A Glance

Metric

Value

Phone numbers collected

~885,000

Largest single dataset (German numbers)

~316,000

Confirmed accounts from German dataset

~43,066

Countries covered in Ledger-related lists

54

Fake wallet apps built

Trezor Suite, Ledger Live, Exodus

Exfiltration channel

Telegram bot

How The Scammers Picked Their Targets

Instead of calling random people, the operator built a system to only go after users who were likely to already own digital assets.

The exposed server contained close to 885,000 phone numbers sorted by country, including over 316,002 German numbers and lists covering Hong Kong, Bulgaria, the UK, US, and Canada. Key points from this stage include:

  • A custom validation tool checked numbers against Crypto.com and Kraken account-verification systems.

  • Confirmed accounts were separated from the raw dataset before any outreach began.

  • Enriched records added names, email addresses, and account details to each lead.

  • Ledger-related lists were organized across 54 country files for wider targeting.

The Phishing And Vishing Combo

This piece of crypto scam news highlights a particularly convincing trick—the scammers paired fake emails with follow-up phone calls. 

Victims first received a branded email, made to look like it came from Crypto.com or Binance, containing a fake support case and verification code. 

A scammer would then call, referencing that same case number to sound legitimate, before pushing the victim toward installing a bogus wallet app or handing over sensitive information. 

His calling infrastructure ran on Asterisk and 3CX, the same kind of software used by legitimate call centers.

Fake Wallet Apps Built To Steal Recovery Phrases

The operation created counterfeit versions of Trezor Suite, Ledger Live, and Exodus. 

The fake Trezor app was especially advanced—it silently ran in the background, waited for the real app to open, then swapped itself in and asked for the wallet's recovery phrase. 

Once entered, the phrase was sent straight to the attacker's Telegram bot along with the victim's IP address. 

The Ledger Live version went a step further on Windows, quietly swapping any copied crypto wallet address with the attacker's own.

A Fake Claude Code Installer Was Also Used

  • The scammers built a near-identical copy of Anthropic's official Claude Code documentation page on a lookalike domain.

  • Visitors who followed the install instructions unknowingly downloaded a hidden, fake Ledger Live app instead.

  • The real Claude Code installer still ran afterward, so nothing looked unusual to the victim.

AI Tools Played A Central Role In Building The Scam

Perhaps the most notable part of this crypto scam news story is how much the operator leaned on AI coding assistants. 

Logs show GitHub Copilot and Claude Code were used to clean phone number lists, write validation scripts, and troubleshoot code. 

When Claude declined to help obfuscate the malware, the operator switched to a different AI model and tried a detailed jailbreak prompt — including inventing a fake persona and a fabricated relationship with the AI — to get around its safety controls. 

It's unclear whether that attempt succeeded, but it shows how attackers are now treating AI safety limits as just another obstacle to work around.

A Similar Scam Pattern Surfaced In The Shiba Inu Community

Social engineering scams like Operation ASTERIX are not isolated. Around the same period, Shiba Inu community advisor Mazrael flagged a fake token migration campaign spreading through Telegram, promising a nonexistent SHIB migration to lure holders into a scam group. 

He confirmed the account behind that group had no connection to ShibaSwap or Shibarium and urged holders to rely only on official channels. 

The pattern mirrors what Rapid7 documented — spoofed branding, fabricated urgency, and a trusted-looking channel used to push victims toward handing over access to their funds.

What This Means Going Forward

Rapid7 has already shared the exposed infrastructure and findings with the relevant authorities, including Apple's security team, to help shut the operation down while parts of it were still active. 

This case of crypto scam news serves as a reminder that scammers are increasingly combining personal data, multi-channel social engineering, and AI tools to make their attacks harder to spot—making it more important than ever to verify any unexpected wallet-related call or email independently before acting on it.

Disclaimer

This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.

Also read: Dollar Slides to Three-Month Lows as Treasury Steps In to Cool Bond Market
WHAT'S YOUR OPINION?
Related News