Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those details to sound legitimate. Investigators also recovered fake wallet apps (including counterfeit Ledger and Trezor software) designed to steal recovery phrases or redirect funds.
How the attack worked
Researchers linked exposed infrastructure to a fraud operation tracked as Operation ASTERIX. The operator used tooling, including AI-assisted steps, to check whether a large list of phone numbers, over 100,000 in total, were associated with specific cryptocurrency platforms. Confirmed leads were then enriched with additional personal data before outreach began.
The attack sequence combined two channels. Victims received phishing emails containing a case number or verification code. Callers then referenced those same details during follow-up phone calls, using outbound dialing infrastructure built on Asterisk and 3CX to scale the operation. In a related track, victims were pushed toward counterfeit wallet software, including fake versions of Trezor Suite, Ledger Live, and Exodus for Windows and macOS, built to capture recovery phrases or redirect funds.
Why it succeeded
The combination of channels is what made this effective. A phishing email alone might be dismissed, but referencing a case number or verification code during a follow-up call created an appearance of continuity and legitimacy. Because the caller already knew the victim was associated with a crypto platform, the interaction felt personalized rather than random.
The fake wallet software added a second failure mode. Victims who avoided the phone-based approach could still be caught by a convincing app update prompt that led them to install counterfeit software and enter their recovery phrase directly.
What to watch for
- Unsolicited support outreach that uses urgency and a case number to build trust
- Callers who reference personal details or account associations to appear legitimate
- Pressure to complete “verification” steps immediately over the phone
- Wallet software arriving via a link, download, or instruction given during a call or email rather than an official app store or vendor site
- Any request to enter a seed or recovery phrase into software received through an unsolicited message
Building resistance
Organizations and individuals handling cryptocurrency accounts should reinforce a few habits. End unexpected support calls and contact the provider only through its official app or website. Never share seed phrases or recovery credentials with anyone, regardless of how convincing their claim to be support sounds. Avoid installing wallet applications from links or downloads sent unsolicited through email or during a call.
It is also worth reminding employees and customers that an attacker knowing a name, email address, or platform association does not prove they work for that company. Scammers may already have verified account associations before making contact, so familiarity with personal details should not be treated as a trust signal.
Key findings
- Rapid7 linked exposed infrastructure to a fraud campaign tracked as “Operation ASTERIX,” containing large phone-number lists and workflow artifacts.
- The operator used tooling (including AI-assisted steps) to check whether phone numbers were associated with specific crypto platforms and then enrich those leads with personal data.
- The attack flow used email + phone in sequence: phishing messages included case numbers/verification codes, which were referenced in follow-up calls to increase credibility.
- Recovered counterfeit wallet software (Trezor Suite, Ledger Live, Exodus for Windows/macOS) was intended to steal recovery phrases or manipulate destination addresses.
- Call operations were supported by outbound dialing infrastructure (Asterisk and 3CX).
Who’s being targeted
- Commonly targeted roles: Executives, Finance, All employees (general awareness), Customer Support, Helpdesk/Service Desk.
- Affected industries: Cryptocurrency exchanges, Consumer financial services.
- Attack channels: email, vishing, website.
- Impersonated: Cryptocurrency exchange support (e.g., Binance/Crypto.com), Hardware wallet or wallet-app support (Trezor Suite / Ledger Live / Exodus).
Red flags to watch for
- Unsolicited support outreach using urgency and a “case number” to build trust
- Caller references personal details to appear legitimate
- Pressure to complete verification steps immediately over the phone
- Software arrives via unsolicited link/message rather than official app store/vendor site
- Request to enter a seed/recovery phrase into software received from a message
- “Update/verification” framing that creates urgency and bypasses normal verification steps
Frequently asked questions
How did the phishing and vishing combination work in this attack?
Victims first received phishing emails containing a case number or verification code, which callers then referenced during follow-up phone calls to appear legitimate.
What made the fake wallet apps dangerous?
Counterfeit versions of Trezor Suite, Ledger Live, and Exodus were built for Windows and macOS and designed to capture wallet recovery phrases or redirect funds.
How did attackers know who to target?
Tooling, including AI-assisted steps, checked whether phone numbers were tied to specific crypto platforms and enriched confirmed leads with personal data before outreach.
What should someone do if they get an unexpected call about their crypto wallet?
Hang up and contact the provider directly through its official app or website, and never share seed or recovery phrases with anyone claiming to be support.
Read the video transcript
You get an email from “Binance Support”, Subject: “Support Case #84721: Account verification code 993004.” Looks legit, right? Behind this is a real campaign called Operation ASTERIX. They used AI tools to sift over a hundred thousand phone numbers, then hit confirmed crypto users with that email first… and a phone call right after. The caller says, “We’re from Crypto.com support about Case #84721. Can you confirm your code and install the latest Ledger Live update we emailed you?” That fake app is a counterfeit wallet designed to grab your recovery phrase and drain funds. Here’s the move: if anyone contacts you about a crypto account or wallet, hang up, ignore the link, and go straight to the official app or website yourself to check.