# Rapid7 uncovers Operation ASTERIX: AI-powered phishing tools targeting crypto wallet recovery phrases

> Source: <https://cryptobriefing.com/rapid7-operation-asterix-crypto-phishing/>
> Published: 2026-08-19 17:27:54+00:00

Via rapid7.com

# Rapid7 uncovers Operation ASTERIX: AI-powered phishing tools targeting crypto wallet recovery phrases

A misconfigured server exposed a fraud operation armed with fake Trezor and Ledger apps, nearly 900,000 phone numbers, and AI-assisted code development

A single misconfigured web server just pulled back the curtain on one of the more methodical crypto fraud operations researchers have seen in recent memory. Rapid7 Labs discovered and documented what it calls Operation ASTERIX, a multi-channel scheme that combined phishing emails, voice calls, and counterfeit wallet applications to steal cryptocurrency recovery phrases from targeted victims.

The exposed directory contained approximately 885,000 phone numbers, automated tools for validating crypto exchange accounts, and fake versions of popular hardware wallet software. The fraudsters used AI coding assistants to build their malicious tools.

## Inside the operation’s playbook

The largest batch of phone numbers in the exposed directory consisted of 316,002 German mobile numbers. The fraudsters used these numbers alongside Asterisk, an open-source telephony platform, to conduct vishing (voice phishing) calls.

On the account validation front, the operation targeted Crypto.com users specifically, running automated checks against their database of phone numbers. The hit rate was 13.6%, meaning roughly one in seven numbers corresponded to an active account.

Once potential victims were identified, the attack chain moved to personalized email outreach and phone calls designed to steer targets toward installing fake wallet applications. The counterfeit apps masqueraded as Trezor Suite and Ledger Live. These bogus applications prompted users to enter their 12-to-24-word recovery phrases, which were then exfiltrated via Telegram.

## AI tools in the attacker’s toolkit

Rapid7’s investigation found evidence that the fraudsters leveraged GitHub Copilot to write and refine their malicious code, including attempts to bypass security safeguards built into the AI assistant itself.

## Targeted precision over brute force

Activity logs recovered from the server showed only 20 lead lookups and 6 phishing emails sent over an approximately two-week period.

Rapid7 coordinated with Apple Security to disclose their findings, and published their report on August 17, 2026.

## What this means for crypto holders

The 13.6% hit rate on Crypto.com account validation is a useful data point for understanding the scale of exposure. If the fraudsters ran that same check against their full database of 885,000 numbers, they’d potentially identify more than 120,000 active exchange users to target.

For exchanges like Crypto.com that were specifically targeted in this operation, the exposure raises questions about how account validation endpoints can be hardened against automated probing. A 13.6% confirmation rate means the API or lookup mechanism was returning enough signal for attackers to build a reliable target list.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
