AI-Aided Crypto Scam Used Phishing + Vishing Combo

eSecurity Planet · High sophistication
Last updated August 20, 2026

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those details to sound legitimate. Investigators also recovered fake wallet apps (including counterfeit Ledger and Trezor software) designed to steal recovery phrases or redirect funds.

How the attack worked

Researchers linked exposed infrastructure to a fraud operation tracked as Operation ASTERIX. The operator used tooling, including AI-assisted steps, to check whether a large list of phone numbers, over 100,000 in total, were associated with specific cryptocurrency platforms. Confirmed leads were then enriched with additional personal data before outreach began.

The attack sequence combined two channels. Victims received phishing emails containing a case number or verification code. Callers then referenced those same details during follow-up phone calls, using outbound dialing infrastructure built on Asterisk and 3CX to scale the operation. In a related track, victims were pushed toward counterfeit wallet software, including fake versions of Trezor Suite, Ledger Live, and Exodus for Windows and macOS, built to capture recovery phrases or redirect funds.

Why it succeeded

The combination of channels is what made this effective. A phishing email alone might be dismissed, but referencing a case number or verification code during a follow-up call created an appearance of continuity and legitimacy. Because the caller already knew the victim was associated with a crypto platform, the interaction felt personalized rather than random.

The fake wallet software added a second failure mode. Victims who avoided the phone-based approach could still be caught by a convincing app update prompt that led them to install counterfeit software and enter their recovery phrase directly.

What to watch for

  • Unsolicited support outreach that uses urgency and a case number to build trust
  • Callers who reference personal details or account associations to appear legitimate
  • Pressure to complete “verification” steps immediately over the phone
  • Wallet software arriving via a link, download, or instruction given during a call or email rather than an official app store or vendor site
  • Any request to enter a seed or recovery phrase into software received through an unsolicited message

Building resistance

Organizations and individuals handling cryptocurrency accounts should reinforce a few habits. End unexpected support calls and contact the provider only through its official app or website. Never share seed phrases or recovery credentials with anyone, regardless of how convincing their claim to be support sounds. Avoid installing wallet applications from links or downloads sent unsolicited through email or during a call.

It is also worth reminding employees and customers that an attacker knowing a name, email address, or platform association does not prove they work for that company. Scammers may already have verified account associations before making contact, so familiarity with personal details should not be treated as a trust signal.

Key findings

  • Rapid7 linked exposed infrastructure to a fraud campaign tracked as “Operation ASTERIX,” containing large phone-number lists and workflow artifacts.
  • The operator used tooling (including AI-assisted steps) to check whether phone numbers were associated with specific crypto platforms and then enrich those leads with personal data.
  • The attack flow used email + phone in sequence: phishing messages included case numbers/verification codes, which were referenced in follow-up calls to increase credibility.
  • Recovered counterfeit wallet software (Trezor Suite, Ledger Live, Exodus for Windows/macOS) was intended to steal recovery phrases or manipulate destination addresses.
  • Call operations were supported by outbound dialing infrastructure (Asterisk and 3CX).

Who’s being targeted

  • Commonly targeted roles: Executives, Finance, All employees (general awareness), Customer Support, Helpdesk/Service Desk.
  • Affected industries: Cryptocurrency exchanges, Consumer financial services.
  • Attack channels: email, vishing, website.
  • Impersonated: Cryptocurrency exchange support (e.g., Binance/Crypto.com), Hardware wallet or wallet-app support (Trezor Suite / Ledger Live / Exodus).

Red flags to watch for

  • Unsolicited support outreach using urgency and a “case number” to build trust
  • Caller references personal details to appear legitimate
  • Pressure to complete verification steps immediately over the phone
  • Software arrives via unsolicited link/message rather than official app store/vendor site
  • Request to enter a seed/recovery phrase into software received from a message
  • “Update/verification” framing that creates urgency and bypasses normal verification steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the phishing and vishing combination work in this attack?

Victims first received phishing emails containing a case number or verification code, which callers then referenced during follow-up phone calls to appear legitimate.

What made the fake wallet apps dangerous?

Counterfeit versions of Trezor Suite, Ledger Live, and Exodus were built for Windows and macOS and designed to capture wallet recovery phrases or redirect funds.

How did attackers know who to target?

Tooling, including AI-assisted steps, checked whether phone numbers were tied to specific crypto platforms and enriched confirmed leads with personal data before outreach.

What should someone do if they get an unexpected call about their crypto wallet?

Hang up and contact the provider directly through its official app or website, and never share seed or recovery phrases with anyone claiming to be support.

Read the video transcript

You get an email from “Binance Support”, Subject: “Support Case #84721: Account verification code 993004.” Looks legit, right? Behind this is a real campaign called Operation ASTERIX. They used AI tools to sift over a hundred thousand phone numbers, then hit confirmed crypto users with that email first… and a phone call right after. The caller says, “We’re from Crypto.com support about Case #84721. Can you confirm your code and install the latest Ledger Live update we emailed you?” That fake app is a counterfeit wallet designed to grab your recovery phrase and drain funds. Here’s the move: if anyone contacts you about a crypto account or wallet, hang up, ignore the link, and go straight to the official app or website yourself to check.

Similar attacks

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026