AI-coded crypto phishing operation targets 885,000 phone numbers

- Rapid7 Labs exposed an active crypto phishing pipeline that used GitHub Copilot to build fake Ledger, Trezor, and Exodus apps.
- The operators validated 43,066 of about 885,000 leaked phone numbers as real crypto exchange users.
- The counterfeit apps harvested wallet recovery phrases and exfiltrated them over Telegram.
Rapid7 Labs uncovered Operation ASTERIX, a crypto fraud pipeline that leveraged AI coding assistants to create fake Ledger, Trezor, and Exodus apps.
It matched 43,066 phone numbers to actual exchange accounts. Any user who self-custodies their crypto is a potential target. The operation was still ongoing when researchers discovered it.
A misconfigured server gave up the whole playbook
An exposed web directory was discovered by Rapid7 researchers Anna Å irokova and Jan Recinsky on campaign infrastructure. Inside were the raw ingredients of a live fraud operation.
The pair’s August 17 report detailed the data trove, which included phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, the fake wallet applications themselves, and code to siphon stolen data out through Telegram.
Most of that tooling was still in use or in development when it leaked. Rapid7 said it could reach out to providers and authorities, including Apple’s security team, while the campaign was happening.
The operation is named after Asterisk, the open-source telephony platform recovered on the server. The operator used Asterisk to make the vishing, or voice-phishing, calls to coincide with fake support emails victims had already received.
In the open directory there were around 885,000 phone numbers, and the largest file was a collection of 316,002 German mobile numbers. Smaller directories included Hong Kong, Bulgaria, the UK, the US, Canadian fintech customers, and Ledger-related lists.
The operators then checked those German numbers against an account checker and confirmed that 43,066 were crypto exchange users. This is a hit rate of about 13.6%, almost one in seven.
A further batch of 5,576 numbers was associated with Binance accounts and lined up for attack. The report also mentioned a Kraken checker and fake emails pretending to be from Crypto.com.
The count of validated targets sits oddly against the activity logs. The logs recovered indicate that there were only 20 lead lookups during a span of about two weeks.
Additionally, six phishing emails were sent, suggesting that the operators favored a slow, hand-selected targeting approach rather than contacting all numbers.
The fake apps asked for a seed phrase
The apps mimic Trezor Suite and Ledger Live, with Exodus also spoofed, and they ask users to enter a recovery phrase of 12 to 24 words that controls a hardware wallet.
That phrase is the master key to the funds, and whoever has it can empty the wallet. The stolen phrases were then exfiltrated via Telegram.
Rapid7 found that AI coding assistants were used across the entire development process, not just to spit out isolated snippets.
Recovered prompts, shell history, and project files show the operator relying on AI tools to package the Electron apps, obfuscate code, fix builds, and prepare the malware for distribution.
The tool was GitHub Copilot. When one model began to refuse parts of the work, the operator switched providers and attempted to break the next model’s safety controls with a custom jailbreak prompt, Rapid7 said.
Earlier in August, Trezor warned 13,689 customers after a breach at its shipping partner ShipMonk exposed names, emails, phone numbers, and addresses, as Cryptopolitan reported.
Ledger and Trezor owners have also received physical letters with QR codes leading to phishing sites, as Cryptopolitan reported back in February.
Hacken, a blockchain security firm, said that phishing and social engineering made up $306 million of the crypto industry’s $482 million in first-quarter losses.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















