Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands, making the outreach feel legitimate by referencing real-looking case numbers and verification codes.
Key findings
- The operation used an exposed Asterisk phone system to validate large volumes of phone numbers against cryptocurrency exchange accounts before targeting victims.
- Confirmed crypto users were then approached with phishing emails, vishing calls, and fake wallet apps.
- Attackers impersonated well-known wallet brands (Ledger, Trezor, Exodus) to increase trust.
- Records were enriched so attackers could cite case numbers and verification codes to make calls sound legitimate.
- The infrastructure spanned multiple countries; researchers notified hosting providers and Apple while parts were still active.
Who’s being targeted
- Commonly targeted roles: All employees (general awareness), Finance, Executives, Anyone who holds/manages cryptocurrency, IT/Helpdesk (handling user-reported scam checks).
- Affected industries: Cryptocurrency exchanges, Financial services, Consumers (crypto investors/users).
- Attack channels: email, vishing.
- Impersonated: Ledger / Trezor / Exodus (crypto wallet provider), Crypto exchange support or wallet provider support.
Awareness takeaways
- Treat unexpected crypto ‘security’ emails and calls as high-risk, even if the sender/caller knows your phone number.
- Be suspicious when someone references case numbers or verification codes to build trust, verify through official channels you initiate.
- Do not install ‘security’ or ‘recovery’ apps from links in messages; only use official app stores and verified publishers.
Red flags to watch for
- Unsolicited security outreach tied to crypto accounts
- Pressure to install an app to resolve an alleged problem
- Brand impersonation (Ledger/Trezor/Exodus) used to build trust
- Caller uses ‘case numbers’/‘verification codes’ to create urgency and credibility
- Unexpected call about crypto account access
- Request to complete verification outside of the official app/site
Read the video transcript
If you’ve got crypto, assume your number’s on a list. Researchers found a fraud ring using an exposed Asterisk phone system to test hundreds of thousands of numbers, then hit confirmed crypto owners with phishing emails, vishing calls, and fake wallet apps posing as Ledger, Trezor, and Exodus. Here’s the trick: you get a ‘Ledger’ or ‘Trezor’ security email, then a call that sounds legit because they drop a case number and a verification code, and push you to install a “recovery” app or follow a link to fix an urgent wallet issue. If you get any crypto ‘security’ email or call out of the blue, don’t tap links, don’t install apps, hang up and open your wallet or exchange app yourself to check for alerts.