885,000 Phone Numbers. Fake Ledger Apps. Crypto Phishing Just Became a Sales Pipeline.

885,000 Phone Numbers. Fake Ledger Apps. Crypto Phishing Just Became a Sales Pipeline.

By Cryptosafekit | CryptoSafeKit | 3 hours ago


c236269b4c4137c53c2fada7a0e0bea76349cf01bad7ff7e316c6ff69c64ac4e.png

Operation ASTERIX shows that scammers are no longer sending the same bad email to everyone. They are trying to find out who actually owns crypto first.

For years, crypto phishing had a certain look.

A badly written email.

A strange domain.

A random Telegram message.

Someone claiming your wallet needed to be “verified.”

Most experienced users learned to recognize the pattern.

But the operation disclosed this week is much more uncomfortable.

Because the scammers were not simply asking:

Who can we trick?

They were asking:

Who already owns crypto—and how much do we know about them before we call?

That difference matters.

A lot.


This Wasn't Random Spam

Rapid7 researchers investigating a campaign they call Operation ASTERIX found an exposed server that effectively revealed the attackers' working environment.

Inside were approximately 885,000 phone numbers, organized by region and source.

The largest single file contained 316,002 German mobile numbers.

But collecting phone numbers was only the beginning.

The attackers had also built tools designed to determine whether those numbers were connected to real cryptocurrency exchange accounts.

In the German dataset, 43,066 numbers reportedly matched Crypto.com accounts.

That is roughly 13.6%.

Other tools targeted additional platforms, and Ledger-related lead files spanned dozens of countries.

Think about the difference.

Traditional phishing:

Send 100,000 people a fake wallet email and hope someone uses crypto.

Targeted phishing:

First identify people who probably already use crypto.
Then learn more about them.
Then contact only the interesting ones.

That is much closer to a sales funnel than spam.

Except the product being sold is trust.

And the conversion event is your recovery phrase.


Imagine Receiving This Call

【Hypothetical Example】

You receive an email.

It looks like it came from an exchange you actually use.

It contains your name.

There is a support-case number.

The email claims someone recently tried to access your account.

Five minutes later, your phone rings.

The caller mentions the same case number.

They know your email address.

They know which exchange you use.

Maybe they even know approximately where you live.

They say:

“We're calling because we detected suspicious wallet activity. We need to secure your funds immediately.”

Then they tell you to install a wallet application.

Maybe Ledger Live.

Maybe Trezor Suite.

Maybe another well-known wallet.

You already know the brand.

The application looks professional.

The caller sounds calm.

The details match the email.

And now the app asks for your recovery phrase.

This is where the scam stops feeling like a scam.


The Phone Call Is More Important Than It Looks

Crypto users are trained to distrust links.

We are less prepared for someone who appears to know things about us.

A generic scammer saying:

“Your wallet is compromised.”

has very little credibility.

Someone saying:

“I'm calling regarding ticket #482731 from the Crypto.com security team. We contacted you earlier at your registered email.”

feels completely different.

The attacker is using accurate information to borrow legitimacy.

That is what makes vishing—voice phishing—so effective.

It is not just the phone call.

It is the context surrounding the phone call.

Email first.

Case number.

Correct name.

Correct service.

Then a human voice.

By the time the victim reaches the malicious software, much of the trust-building has already happened.


The Fake Wallet May Not Look Fake

This is the part of the ASTERIX investigation that should worry hardware-wallet users.

Researchers recovered counterfeit versions of:

Trezor Suite, Ledger Live and Exodus.

The fake software was not necessarily a crude screen saying:

GIVE US YOUR SEED.

Some of it was designed to behave much more convincingly.

According to reporting based on the Rapid7 investigation, one fake Trezor application could wait for the legitimate Trezor Suite to run, interfere with that process, and place the malicious interface in front of the user.

The fake interface then requested recovery words.

The submitted phrase could be sent to the attacker, while the victim was presented with an error or redirected toward a legitimate-looking destination.

From the user's perspective:

They opened Trezor.

Trezor appeared.

Trezor asked for recovery information.

Why would they suspect anything?

That is precisely the problem.


The Ledger Version Had a Different Trick

The counterfeit Ledger Live tooling reportedly included another familiar attack:

clipboard address replacement.

You copy a cryptocurrency address.

The malicious software changes the contents of your clipboard.

You paste.

The address looks like a long string of meaningless characters.

You confirm.

The hardware wallet may still be functioning exactly as designed.

But if you do not verify the complete receiving address on the trusted display, the device cannot know which address you intended to send to.

This is a recurring lesson in hardware-wallet security:

Private-key isolation does not automatically guarantee transaction intent.

Those are two different problems.


Then the Attackers Added AI

Operation ASTERIX also contained evidence that the operators used AI coding assistants during development.

Researchers found session logs involving tools such as GitHub Copilot and Claude Code.

When one system reportedly refused to help with certain code-obfuscation requests, the operators tried other approaches and other models.

Rapid7's evidence did not establish that every attempted safety bypass succeeded, so it would be misleading to claim that AI autonomously built the operation.

But the broader pattern is still important:

AI reduced some of the friction involved in building, debugging and modifying the attack infrastructure.

That changes the economics of scams.

Attackers do not need AI to invent phishing.

Phishing existed long before ChatGPT.

What AI can do is help a small operation move faster:

rewrite code,

debug installers,

produce localized text,

build convincing interfaces,

process datasets,

adapt tools,

and iterate.

That is enough.


The Scariest Part Isn't the AI

I actually think focusing too much on the AI angle misses the most important lesson.

The dangerous part is the targeting pipeline.

Collect data.

Identify likely crypto users.

Enrich the data.

Send believable email.

Follow with believable call.

Install believable application.

Request recovery phrase.

Exfiltrate secret.

Each individual technique is familiar.

Put them together and you get something much more convincing than:

“Dear sir, your Bitcoin account is blocked.”

The scam becomes personalized.

And personalization changes human behavior.


Your Phone Number Is Becoming Part of Your Crypto Attack Surface

Most people do not think of their phone number as a crypto security secret.

It isn't a private key.

It isn't a seed phrase.

It cannot sign Bitcoin transactions.

But information does not need to directly control a wallet to be useful to an attacker.

Suppose someone knows:

your phone number,

your real name,

your email,

which exchange you use,

and that you previously bought a hardware wallet.

None of those facts individually reveals your private key.

Together, they create an extremely useful social-engineering profile.

This is why recent hardware-wallet customer-data incidents matter even when private keys remain untouched.

Attackers increasingly need context.

Context makes phishing believable.


“But I Use a Hardware Wallet”

Good.

A hardware wallet can meaningfully reduce exposure of private keys to a general-purpose phone or computer.

But a hardware wallet cannot prevent you from:

installing fake software,

entering a recovery phrase into that software,

approving the wrong address,

trusting a fake support agent,

or believing a convincing phone call.

The device handles one security boundary.

You handle the others.

This is the distinction I keep coming back to when writing about self-custody at CryptoSafeKit:

Hardware protects keys. It does not automatically protect decisions.

I broke down the recovery-phrase side of this problem in more detail here:

CryptoSafeKit — Can Your Ledger Seed Phrase Be Stolen? 7 Real Attack Vectors

That is the only promotion I would put in this article.

The ASTERIX story is strong enough to stand on its own.


The Most Important Rule Has Not Changed

The attacks are getting more professional.

The emails may improve.

The software may improve.

The calls may become more personalized.

AI may help criminals work faster.

But the most important defense remains surprisingly boring:

A person who legitimately helps you with a wallet should not need possession of your recovery phrase.

If someone calls unexpectedly and eventually reaches:

“Enter your 12 or 24 words…”

everything before that point becomes irrelevant.

Their name does not matter.

Their case number does not matter.

Their knowledge of your account does not matter.

Their professional accent does not matter.

Their website design does not matter.

Their software does not matter.

Stop.


Download Source Matters More Than Appearance

This incident also reinforces another rule I think users underestimate:

Do not judge wallet software by how professional it looks.

Interfaces can be copied.

Logos can be copied.

Colors can be copied.

Installers can be copied.

Documentation can be copied.

Attackers in ASTERIX reportedly even created a fake Claude Code page that closely resembled the legitimate site and used it as part of a delivery chain involving fake Ledger software.

That is why:

“It looked official.”

is not verification.

The download origin matters.

The domain matters.

The signing information matters.

How you reached the site matters.


One Thing I Would Change After Reading This Report

I would become much more suspicious of security calls that contain correct personal information.

Previously, knowing my name might create credibility.

Now I would treat it differently.

A stranger knowing my name, phone number and exchange does not prove they work for the exchange.

It may prove that my information exists in a database.

That distinction is important.

Modern scams increasingly operate on leaked, purchased, scraped or otherwise acquired personal data.

So this:

“But they knew which exchange I used.”

should no longer be treated as authentication.


If Someone Calls You About Crypto

My response would be simple.

I would not troubleshoot the wallet during the call.

I would not install anything they send.

I would not read verification codes aloud.

I would not enter recovery words.

I would end the call.

Then independently access the service through a trusted method I already know.

Not the caller's link.

Not their phone number.

Not their installer.

Not their QR code.

That little break destroys much of the attacker's momentum.

And momentum is exactly what social engineering depends on.


Crypto Security Is Becoming Less About Spotting Bad Grammar

There was a period when security advice could be:

Look for spelling mistakes.

That era is disappearing.

The new question is not:

“Does this look professional?”

The new question is:

“Can I independently verify why this interaction is happening?”

Because professional-looking scams are now cheap.

Good writing is cheap.

Good design is cheap.

Cloned software interfaces are achievable.

Personalized scripts are achievable.

Phone calls scale.

Data can be enriched automatically.

So the defense has to move deeper than appearance.


885,000 Phone Numbers Is the Wrong Number to Focus On

The headline number is impressive.

885,000.

But I think a much smaller number matters more:

43,066.

That is how many accounts were reportedly identified from one German dataset using an account-validation process.

The implication is more important than the absolute number.

The attacker was trying to answer:

Which of these people are worth targeting?

That is the evolution.

From spam.

To segmentation.

From segmentation.

To qualified leads.

From qualified leads.

To personalized social engineering.

It sounds like digital marketing.

Because structurally, it is.


Except the Customer Is the Victim

A legitimate company builds a funnel:

Audience.

Lead.

Qualification.

Follow-up.

Conversion.

Retention.

Operation ASTERIX appears to have adapted similar logic for fraud:

Dataset.

Crypto-user validation.

Enrichment.

Phishing.

Phone call.

Fake wallet.

Seed phrase.

That may be the best way to understand modern crypto scams.

They are becoming less like random messages.

And more like operations.


The Question I Keep Coming Back To

Suppose your phone rings tonight.

The caller knows:

your name,

your exchange,

your email,

and enough account information to sound convincing.

They claim your crypto is in danger.

Would that information make you trust them more?

A year ago, I think many people would say yes.

After reading about Operation ASTERIX, my answer is the opposite.

The more personal information an unsolicited crypto caller knows about me, the more cautious I become.

Because that information may be exactly what put me on the target list.


One Question for the Comments

Have you ever received a crypto-related call or email that knew real information about you?

Not just a generic spam message.

Your name?

Exchange?

Wallet brand?

Recent transaction?

Country?

I'm curious how personalized these attacks already look from the user side.

Please don't post phone numbers, email addresses, wallet addresses, balances, recovery phrases or private keys in the comments.

Security disclaimer: This article is for educational purposes. Operation ASTERIX does not establish that Ledger, Trezor, Exodus, Binance, Crypto.com or Kraken suffered the same underlying breach; the reported operation used datasets, validation tooling and impersonation infrastructure to identify and target crypto users. Never provide a recovery phrase, private key, PIN or passphrase to an unsolicited caller, website or software application.

How do you rate this article?

5



CryptoSafeKit
CryptoSafeKit

CryptoSafeKit shares practical, independent guides on crypto security, self-custody, hardware wallets, recovery phrase protection, phishing prevention, and safer Web3 habits. Our goal is to help everyday users understand risks, avoid common mistakes, and take greater control of their digital assets.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?