Fraud Ring Targets Crypto Users via Phone + Phish

About DFIR · High sophistication
Last updated August 18, 2026

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands, making the outreach feel legitimate by referencing real-looking case numbers and verification codes.

Key findings

  • The operation used an exposed Asterisk phone system to validate large volumes of phone numbers against cryptocurrency exchange accounts before targeting victims.
  • Confirmed crypto users were then approached with phishing emails, vishing calls, and fake wallet apps.
  • Attackers impersonated well-known wallet brands (Ledger, Trezor, Exodus) to increase trust.
  • Records were enriched so attackers could cite case numbers and verification codes to make calls sound legitimate.
  • The infrastructure spanned multiple countries; researchers notified hosting providers and Apple while parts were still active.

Who’s being targeted

  • Commonly targeted roles: All employees (general awareness), Finance, Executives, Anyone who holds/manages cryptocurrency, IT/Helpdesk (handling user-reported scam checks).
  • Affected industries: Cryptocurrency exchanges, Financial services, Consumers (crypto investors/users).
  • Attack channels: email, vishing.
  • Impersonated: Ledger / Trezor / Exodus (crypto wallet provider), Crypto exchange support or wallet provider support.

Awareness takeaways

  • Treat unexpected crypto ‘security’ emails and calls as high-risk, even if the sender/caller knows your phone number.
  • Be suspicious when someone references case numbers or verification codes to build trust, verify through official channels you initiate.
  • Do not install ‘security’ or ‘recovery’ apps from links in messages; only use official app stores and verified publishers.

Red flags to watch for

  • Unsolicited security outreach tied to crypto accounts
  • Pressure to install an app to resolve an alleged problem
  • Brand impersonation (Ledger/Trezor/Exodus) used to build trust
  • Caller uses ‘case numbers’/‘verification codes’ to create urgency and credibility
  • Unexpected call about crypto account access
  • Request to complete verification outside of the official app/site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If you’ve got crypto, assume your number’s on a list. Researchers found a fraud ring using an exposed Asterisk phone system to test hundreds of thousands of numbers, then hit confirmed crypto owners with phishing emails, vishing calls, and fake wallet apps posing as Ledger, Trezor, and Exodus. Here’s the trick: you get a ‘Ledger’ or ‘Trezor’ security email, then a call that sounds legit because they drop a case number and a verification code, and push you to install a “recovery” app or follow a link to fix an urgent wallet issue. If you get any crypto ‘security’ email or call out of the blue, don’t tap links, don’t install apps, hang up and open your wallet or exchange app yourself to check for alerts.

Similar attacks

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
OkoBot Fakes Wallet App Screens to Steal Seed Phrases

OkoBot Fakes Wallet App Screens to Steal Seed Phrases

A real malware campaign called OkoBot is infecting Windows PCs and then showing a fake “recovery phrase” prompt inside legitimate Ledger and Trezor desktop apps. Victims are tricked into typing their wallet seed phrase into a malicious page that looks like it came from the trusted app, allowing…

July 15, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026