Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Ethereum Exchanges

    Cybersecurity Firm Maps Crypto Phishing Campaign to 885,000 Numbers

    20 August 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Cybersecurity Firm Maps Crypto Phishing Campaign To 885,000 Numbers
    Cybersecurity Firm Maps Crypto Phishing Campaign To 885,000 Numbers

    Rapid7 has disclosed details of a large-scale cryptocurrency phishing operation dubbed “Operation Asterix,” designed to target people through phone and email lures that ultimately aim to extract crypto seed phrases. The campaign reportedly reached into datasets covering roughly 885,000 phone numbers across multiple regions, with the largest tranche tied to Germany.

    In Rapid7’s investigation, the phishing workflow included targeting users connected to the Binance exchange, producing 5,576 accounts matched to exchange users that were queued for attack. The firm also found evidence of fake communications impersonating Crypto.com, highlighting how the operation blended vishing tactics with exchange-branded messaging.

    Key takeaways

    • Rapid7 traced Operation Asterix to a dataset of about 885,000 phone numbers, with Germany the largest source (316,002 numbers).
    • The campaign identified 43,066 accounts tied to crypto exchange users and generated 5,576 Binance-matched targets for follow-on attacks.
    • Attackers used fake Ledger, Trezor, and Exodus applications to pressure victims into revealing seed phrases.
    • Rapid7’s artifacts suggest automated tooling, including “checker” logic for Kraken account validation, alongside AI-assisted components.

    Operation Asterix: scale, filtering, and “hit rate”

    Rapid7’s report describes Operation Asterix as a campaign built around “targeting” rather than indiscriminate spam. According to the firm, attackers matched 43,066 accounts to cryptocurrency users using data validated against the broader German dataset containing more than 316,000 mobile numbers. Rapid7 estimates this translates to an approximate “hit rate” of 13.6% for the validated matching process.

    The company also points to recovered artifacts indicating a separate checker function aimed at bulk-validating phone numbers against accounts associated with Kraken. This matters because it suggests the operation was not limited to a single exchange or geography; instead, it used verification steps to determine which phone numbers were most likely to correspond to crypto users.

    How victims were lured: impersonation and seed-phrase extraction

    At the center of Rapid7’s findings is the social-engineering phase of the campaign. Analysts Anna Sirokova and Jan Recinsky write that the attackers attempted to move victims toward fake applications impersonating well-known self-custody brands, including Ledger, Trezor, and Exodus.

    Rapid7 says victims were driven to these impersonation surfaces with the objective of obtaining seed phrases—an outcome that can permanently compromise funds if users enter them into attacker-controlled flows. The phishing operation also used direct contact channels: attackers reached out through fake support emails and phone inquiries designed to look legitimate.

    Rapid7’s findings also emphasize the operational chain—how contact was established, which targets were selected, and how the campaign progressed toward data exfiltration. While the report focuses on observed behavior in artifacts recovered by the security team, the practical implication for users is straightforward: even when the message appears to come from a brand or support channel, the risk is highest when the interaction attempts to steer victims toward entering recovery information.

    Binance and Crypto.com were among the exchanges impersonated

    One of the most consequential elements in Rapid7’s disclosure is how the campaign narrowed down real exchange users. The report states that it identified 5,576 accounts matched to users on Binance that were queued for attack. Rapid7 also reports that recovered logs included fake emails impersonating Crypto.com.

    For traders and long-term holders, this pairing of exchange-linked targeting with brand impersonation underscores a common problem: attackers often aim to compromise trust in familiar service identities. Rather than relying solely on generic phishing, Operation Asterix appears to have used verification steps and exchange references to increase the likelihood of a victim responding.

    Rapid7’s account of the target composition further indicates that the campaign’s infrastructure included lists beyond Germany. The largest file contained 316,002 German mobile numbers, while additional directories reportedly covered phone numbers associated with regions including Hong Kong, Bulgaria, and the UK, alongside US and Canadian fintech-related lists and Ledger-related lists.

    Broader crypto security context: a persistent human-layer threat

    Operation Asterix lands in a wider pattern of crypto fraud that repeatedly exploits users rather than breaking underlying protocols. The article notes that, according to blockchain security company Hacken, phishing and social engineering drove most of the crypto industry’s losses in the first quarter, accounting for $306 million out of a reported total of $482 million lost.

    This is consistent with earlier incidents referenced in the same material. For example, it points to a Trezor-related personal data breach involving its shipping provider ShipMonk reported in August, a separate Ethereum-related case in July where a crypto investor lost nearly $1 million after approving a malicious phishing token approval transaction, and a prior episode in November 2023 where a fake Ledger Live app placed on the Microsoft Store led to theft totaling $588,000 across 38 transactions.

    Taken together, these examples reinforce that crypto users face two different—but overlapping—risk categories: technical compromise through malicious software and direct loss from social-engineering flows that trick users into granting access or revealing recovery material.

    What to watch next

    As Rapid7’s disclosure shows, campaigns like Operation Asterix increasingly combine datasets, exchange validation, and impersonation of popular self-custody brands—meaning the most urgent question for users isn’t only whether phishing exists, but whether attackers can improve their targeting accuracy. Investors should watch for follow-on reporting from security teams on the specific tooling and any indicators of compromise tied to the fake Ledger, Trezor, and Exodus lures, while continuing to treat unsolicited support messages and “wallet recovery” requests as high-risk until independently verified.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Liquid “white Hats” Return $270m In Btc As Network Readies Restart

    Liquid “white hats” return $270M in BTC as network readies restart

    1 hour ago
    White-Hat Wallets Return $270m In Bitcoin As Network Readies Restart

    White-hat wallets return $270M in Bitcoin as network readies restart

    2 hours ago
    Capital B Buys 376 Btc For $29m, Lifts Holdings To 3,521 Btc

    Capital B Buys 376 BTC for $29M, Lifts Holdings to 3,521 BTC

    3 hours ago
    Polish Prosecutors Seek Pretrial Detention In Zondacrypto Probe

    Polish Prosecutors Seek Pretrial Detention in Zondacrypto Probe

    4 hours ago
    Ethereum Foundation Flags 2 “must-Ship” Eips For The Hegotá Upgrade

    Ethereum Foundation Flags 2 “Must-Ship” EIPs for the Hegotá Upgrade

    6 hours ago
    Uk Regulator Considers Easing Prediction Markets Ban, Report Says

    UK Regulator Considers Easing Prediction Markets Ban, Report Says

    8 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    11 hours ago

    Latest News

    • Liquid “white hats” return $270M in BTC as network readies restart
    • White-hat wallets return $270M in Bitcoin as network readies restart
    • Capital B Buys 376 BTC for $29M, Lifts Holdings to 3,521 BTC
    • Polish Prosecutors Seek Pretrial Detention in Zondacrypto Probe
    • Ethereum Foundation Flags 2 “Must-Ship” EIPs for the Hegotá Upgrade
    • UK Regulator Considers Easing Prediction Markets Ban, Report Says
    • Ethereum Foundation Sets Two ‘Must-Ship’ EIPs for Hegotà Upgrade
    • Bitcoin Holds Near $79K as Analyst Flags Key Levels for Next Move
    • UK Regulator Considers Easing Ban on Prediction Markets: Report
    • CoinShares: Bitcoin inflows track Fed rate bets, not an exit

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Kraken Pro 300x250
    AVATRADE

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!