All Crypto Blogs

Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbers

cointelegraph.com · Aug 20, 2026 at 12:35

Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbers
cointelegraph.com Aug 20, 2026

Rapid7 unveiled a new cryptocurrency phishing campaign targeting 885,000 phone numbers, aiming to steal investors’ holdings by redirecting them to fake wallet provider websites.

Cybersecurity firm Rapid7 unveiled a new cryptocurrency phishing campaign known as Operation Asterix, targeting roughly 885,000 phone numbers from several countries to steal cryptocurrency investors’ assets.

The phishing campaign led to 5,576 accounts matched to users on crypto exchange Binance, which were queued for attack, while the recovered logs also showed fake emails impersonating Crypto.com, according to a Monday report by Rapid7.

Of the 885,000 phone numbers, the largest file included 316,002 German mobile numbers, with additional directories covering Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and additional Ledger-related lists. 

Phishing attacks and social engineering scams drove the majority of the crypto industry’s losses in the first quarter of the year, accounting for $306 million out of the total $482 million lost, according to blockchain security company Hacken.

As part of the Asterix phishing campaign detailed by Rapid7 analysts Anna Sirokova and Jan Recinsky, attackers drove victims to fake apps impersonating Ledger, Trezor, and Exodus, seeking to steal their seed phrases. Attackers reached out to victims through fake support emails and phone inquiries.

Operation Aseterix kill chain from acquisition to exfiltration. Source: Rapid7.

Cointelegraph has contacted the analysts for further comment on what they found regarding target filtering, hardware wallet spoofing and self-custody vulnerabilities. We will update this article when they reply.

Earlier in August, wallet provider Trezor reported a breach of personal data affecting about 14,000 users through its shipping provider, ShipMonk.  

In July, a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum. 

In November 2023, a fake Ledger Live app on the Microsoft Store resulted in the theft of $588,000 across 38 transactions. 

Related: DefiLlama delayed mobile launch over phishing apps on Apple Store, founder says

Source

This article is syndicated for educational reading. For the latest updates, visit the original publisher.

Read on cointelegraph.com

Recently Used