880,000+ mobile numbers targeted—hackers queued up to steal
Security firm Rapid7 has just revealed a large-scale phishing operation codenamed Ostatrix. A total of 885,000 phone numbers were collected with precision. Just one file from Germany contains 316,000 entries. There are also records from Hong Kong, the UK, the US, Bulgaria, and Canada—plus even lists of hardware wallet usernames.
The most outrageous part is that this data isn’t just for show; it’s being used to get work done. Binance alone matched 5,576 accounts—waiting in line to be attacked. The attackers created fake Ledger, Trezor, and Exodus wallet apps, then tricked victims into handing over seed phrases using fake customer-service emails and phone calls. The whole process is more professional than that of legitimate companies.
For the German data, 43,000 numbers were matched to exchange accounts, hitting a 13.6% success rate—14 out of every 100 people fell for it. That conversion rate is top-tier in any industry. Unfortunately, it’s being applied in the wrong place.
Even AI has been pulled into this war: bulk verification of numbers, forged emails, fully automated pipelines. The scammers’ pace of technical iteration is faster than that of many legitimate projects. Just imagine what that looks like—it’s heartbreaking.
Data shows that in this year’s first quarter, phishing and social engineering attacks accounted for more than 60% of the total losses in the crypto industry—over $300 million. As protocol code gets harder to break, human nature will always be the best entry point.
Wallet providers shouldn’t just shift blame either. In August, a logistics partner leaked data on 14,000 users. In July, someone signed an authorization with the wrong details—$1 million was gone. Even if cold wallets are safer, they can’t stop you from handing your seed phrase to them yourself.
Remember: Official parties will never ask you for your seed phrase proactively. Whoever asks for it is a thief. If you encounter a fake app or fake email, pause for three seconds and verify on the official website—so you’re not one of the hackers’ 13.6%.
Have you received phishing texts like this? Share your anti-scam tips in the comments.
Click the avatar to watch the livestream.
Every day I’ll help you follow the latest crypto security hot topics. Not just what happened in the news—but also the logic and opportunities behind it 👉🦖
#比特币 #加密安全
Security firm Rapid7 has just revealed a large-scale phishing operation codenamed Ostatrix. A total of 885,000 phone numbers were collected with precision. Just one file from Germany contains 316,000 entries. There are also records from Hong Kong, the UK, the US, Bulgaria, and Canada—plus even lists of hardware wallet usernames.
The most outrageous part is that this data isn’t just for show; it’s being used to get work done. Binance alone matched 5,576 accounts—waiting in line to be attacked. The attackers created fake Ledger, Trezor, and Exodus wallet apps, then tricked victims into handing over seed phrases using fake customer-service emails and phone calls. The whole process is more professional than that of legitimate companies.
For the German data, 43,000 numbers were matched to exchange accounts, hitting a 13.6% success rate—14 out of every 100 people fell for it. That conversion rate is top-tier in any industry. Unfortunately, it’s being applied in the wrong place.
Even AI has been pulled into this war: bulk verification of numbers, forged emails, fully automated pipelines. The scammers’ pace of technical iteration is faster than that of many legitimate projects. Just imagine what that looks like—it’s heartbreaking.
Data shows that in this year’s first quarter, phishing and social engineering attacks accounted for more than 60% of the total losses in the crypto industry—over $300 million. As protocol code gets harder to break, human nature will always be the best entry point.
Wallet providers shouldn’t just shift blame either. In August, a logistics partner leaked data on 14,000 users. In July, someone signed an authorization with the wrong details—$1 million was gone. Even if cold wallets are safer, they can’t stop you from handing your seed phrase to them yourself.
Remember: Official parties will never ask you for your seed phrase proactively. Whoever asks for it is a thief. If you encounter a fake app or fake email, pause for three seconds and verify on the official website—so you’re not one of the hackers’ 13.6%.
Have you received phishing texts like this? Share your anti-scam tips in the comments.
Click the avatar to watch the livestream.
Every day I’ll help you follow the latest crypto security hot topics. Not just what happened in the news—but also the logic and opportunities behind it 👉🦖
#比特币 #加密安全