
Rapid7 has disclosed details of a large-scale cryptocurrency phishing operation dubbed “Operation Asterix,” designed to target people through phone and email lures that ultimately aim to extract crypto seed phrases. The campaign reportedly reached into datasets covering roughly 885,000 phone numbers across multiple regions, with the largest tranche tied to Germany.
In Rapid7’s investigation, the phishing workflow included targeting users connected to the Binance exchange, producing 5,576 accounts matched to exchange users that were queued for attack. The firm also found evidence of fake communications impersonating Crypto.com, highlighting how the operation blended vishing tactics with exchange-branded messaging.
Rapid7’s report describes Operation Asterix as a campaign built around “targeting” rather than indiscriminate spam. According to the firm, attackers matched 43,066 accounts to cryptocurrency users using data validated against the broader German dataset containing more than 316,000 mobile numbers. Rapid7 estimates this translates to an approximate “hit rate” of 13.6% for the validated matching process.
The company also points to recovered artifacts indicating a separate checker function aimed at bulk-validating phone numbers against accounts associated with Kraken. This matters because it suggests the operation was not limited to a single exchange or geography; instead, it used verification steps to determine which phone numbers were most likely to correspond to crypto users.
At the center of Rapid7’s findings is the social-engineering phase of the campaign. Analysts Anna Sirokova and Jan Recinsky write that the attackers attempted to move victims toward fake applications impersonating well-known self-custody brands, including Ledger, Trezor, and Exodus.
Rapid7 says victims were driven to these impersonation surfaces with the objective of obtaining seed phrases—an outcome that can permanently compromise funds if users enter them into attacker-controlled flows. The phishing operation also used direct contact channels: attackers reached out through fake support emails and phone inquiries designed to look legitimate.
Rapid7’s findings also emphasize the operational chain—how contact was established, which targets were selected, and how the campaign progressed toward data exfiltration. While the report focuses on observed behavior in artifacts recovered by the security team, the practical implication for users is straightforward: even when the message appears to come from a brand or support channel, the risk is highest when the interaction attempts to steer victims toward entering recovery information.
One of the most consequential elements in Rapid7’s disclosure is how the campaign narrowed down real exchange users. The report states that it identified 5,576 accounts matched to users on Binance that were queued for attack. Rapid7 also reports that recovered logs included fake emails impersonating Crypto.com.
For traders and long-term holders, this pairing of exchange-linked targeting with brand impersonation underscores a common problem: attackers often aim to compromise trust in familiar service identities. Rather than relying solely on generic phishing, Operation Asterix appears to have used verification steps and exchange references to increase the likelihood of a victim responding.
Rapid7’s account of the target composition further indicates that the campaign’s infrastructure included lists beyond Germany. The largest file contained 316,002 German mobile numbers, while additional directories reportedly covered phone numbers associated with regions including Hong Kong, Bulgaria, and the UK, alongside US and Canadian fintech-related lists and Ledger-related lists.
Operation Asterix lands in a wider pattern of crypto fraud that repeatedly exploits users rather than breaking underlying protocols. The article notes that, according to blockchain security company Hacken, phishing and social engineering drove most of the crypto industry’s losses in the first quarter, accounting for $306 million out of a reported total of $482 million lost.
This is consistent with earlier incidents referenced in the same material. For example, it points to a Trezor-related personal data breach involving its shipping provider ShipMonk reported in August, a separate Ethereum-related case in July where a crypto investor lost nearly $1 million after approving a malicious phishing token approval transaction, and a prior episode in November 2023 where a fake Ledger Live app placed on the Microsoft Store led to theft totaling $588,000 across 38 transactions.
Taken together, these examples reinforce that crypto users face two different—but overlapping—risk categories: technical compromise through malicious software and direct loss from social-engineering flows that trick users into granting access or revealing recovery material.
As Rapid7’s disclosure shows, campaigns like Operation Asterix increasingly combine datasets, exchange validation, and impersonation of popular self-custody brands—meaning the most urgent question for users isn’t only whether phishing exists, but whether attackers can improve their targeting accuracy. Investors should watch for follow-on reporting from security teams on the specific tooling and any indicators of compromise tied to the fake Ledger, Trezor, and Exodus lures, while continuing to treat unsolicited support messages and “wallet recovery” requests as high-risk until independently verified.
This article was originally published as Cybersecurity Firm Maps Crypto Phishing Campaign to 885,000 Numbers on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.