Cybersecurity firm Rapid7 has uncovered a cryptocurrency phishing campaign named Operation Asterix, which targeted approximately 885,000 phone numbers across multiple countries to steal assets from digital asset investors.
According to a report published on Monday by Rapid7 analysts Anna Sirokova and Jan Recinsky, the campaign queued 5,576 accounts matched to users on cryptocurrency exchange Binance for attack. Recovered logs also revealed fake emails impersonating Crypto.com.
The targeted phone numbers were drawn from several regional datasets. The largest file contained 316,002 German mobile numbers, alongside directories covering Hong Kong, Bulgaria, the United Kingdom, the United States, Canadian fintech companies, and additional Ledger-related lists.
As part of the operation, attackers directed victims toward fraudulent applications impersonating popular self-custody solutions including Ledger, Trezor, and Exodus in an effort to capture seed phrases. Perpetrators reached out to victims via fake support emails and telephone inquiries, utilizing artificial intelligence tools as a significant component of the campaign.
From the larger German dataset of over 316,000 phone numbers, attackers successfully matched 43,066 accounts to cryptocurrency users with exchange accounts, yielding a hit rate of approximately 13.6%. The report also noted the use of a validator designed to check phone numbers against accounts on the Kraken exchange.
Blockchain security firm Hacken reported that phishing attacks and social engineering scams drove the majority of the cryptocurrency industry's losses in the first quarter of the year, accounting for $306 million out of a total $482 million lost.


