Security researchers have pulled back the curtain on an industrial-scale crypto phishing operation. According to reporting by Cointelegraph, cybersecurity firm Rapid7 detailed a campaign it calls Operation Asterix, which targeted roughly 885,000 phone numbers across several countries in an effort to drain cryptocurrency investors’ assets.
The scale of the target list
The recovered data paints a picture of careful, geographically organized targeting. Of the 885,000 phone numbers, the single largest file held 316,002 German mobile numbers, with additional directories covering Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies, and Ledger-related lists, Cointelegraph reports.
The campaign also linked numbers to real exchange users. Rapid7 found 5,576 accounts matched to users on crypto exchange Binance that had been queued for attack, while recovered logs showed fake emails impersonating Crypto.com. Within the German dataset specifically, attackers matched 43,066 accounts for an approximate 13.6% hit rate.
How the trap worked
The mechanics were built to harvest the one secret that undoes self-custody: the seed phrase. Rapid7 analysts Anna Sirokova and Jan Recinsky described a kill chain in which attackers drove victims toward fake apps impersonating Ledger, Trezor, and Exodus, reaching out through counterfeit support emails and phone inquiries to coax users into surrendering their recovery phrases.
A costly category of attack
Operation Asterix fits a broader and expensive trend. Cointelegraph notes that, per blockchain security company Hacken, phishing attacks and social engineering scams drove the majority of the crypto industry’s losses in the first quarter of the year — accounting for $306 million out of a total $482 million lost.
The lesson for holders is unglamorous but decisive: legitimate hardware-wallet makers and exchanges never ask for a seed phrase, and no genuine “support” call will either. As campaigns like this one show, the weakest link is rarely the cryptography — it’s the convincing message that arrives on your phone.
This article covers a security threat; readers should treat unsolicited crypto “support” contact with caution and never share recovery phrases.
Written for Red Robot with AI assistance and human editing. Based on reporting by Cointelegraph.