AI-powered crypto phishing

A misconfigured web server has pulled back the curtain on one of the more calculated AI-powered crypto phishing operations security researchers have documented this year. Cybersecurity firm Rapid7 says it stumbled onto the exposed infrastructure almost by accident, and what it found inside was a fully built fraud machine: nearly 900,000 phone numbers, automated account-checking tools, counterfeit wallet software, and code written with the help of mainstream AI coding assistants. Rapid7 has named the campaign Operation ASTERIX, and it offers a rare, detailed look at how generative AI tools are being folded into cryptocurrency phishing campaigns that once required far more manual effort to run.

Key takeaways

  • Rapid7 uncovered Operation ASTERIX, an AI-powered crypto phishing campaign, after finding a misconfigured, exposed server.

  • The exposed dataset held roughly 885,000 phone numbers, including 316,002 German mobile numbers, and produced 43,066 matched Crypto.com accounts.

  • Attackers built fake wallet apps mimicking Trezor Suite, Ledger Live, and Exodus, alongside phishing pages spoofing Crypto.com and Binance.

  • Coding assistants GitHub Copilot and Claude Code were used to write, package, and refine the malicious tools, and operators tried switching AI models after hitting safety restrictions.

  • Rapid7 notified affected providers and authorities, including Apple’s security team, after documenting the operation.

Rapid7 Uncovers Operation ASTERIX and Its Real Scale

Operation ASTERIX combined phishing emails, voice calls, and fake wallet software into a single, coordinated fraud pipeline, and the numbers behind it are striking. Rapid7’s exposed directory contained approximately 885,000 phone numbers spread across multiple datasets, each one apparently gathered to feed the operation’s targeting engine.

Discovery and Scope of Operation ASTERIX

The largest single batch inside that trove was a German dataset holding 316,002 mobile numbers. Rather than blasting messages at random, the operators ran that list through automated validation tools designed to confirm which numbers belonged to active cryptocurrency exchange accounts. That step mattered: it turned a mass of anonymous digits into a curated list of likely victims.

Use of Phone Datasets and Account Validation

From the German numbers alone, the attackers identified 43,066 Crypto.com accounts. According to Crypto Briefing’s reporting on the same server, the validation checks against Crypto.com’s systems returned a hit rate of 13.6%, meaning roughly one in seven numbers tested corresponded to a real, active account. Applied across the full 885,000-number database, that same ratio could theoretically point to more than 120,000 active exchange users worth targeting — a detail that underscores just how much reach a phishing campaign can gain once it pairs stolen or scraped phone data with a reliable validation tool.

This is where the operation stops looking like a scattershot scam and starts looking like a targeting system. Once a number was confirmed live, Rapid7 says the campaign layered on enriched records — names, contact details, locations, and account-related information in some cases — to make follow-up outreach feel personal rather than generic.

Phishing Methods: Brand Impersonation and Fake Wallet Applications

Confirmed targets were funneled into a multi-channel pressure campaign designed to look like legitimate customer support. Coordinated emails and phone calls referenced matching account details, which Rapid7 says made the impersonation far more convincing than a typical mass phishing blast.

Impersonation of Major Crypto Brands

The phishing infrastructure directly impersonated Crypto.com and Binance, two of the industry’s largest exchanges, giving the outreach an air of authenticity that pushed targets toward the next stage of the trap.

Deployment of Counterfeit Wallet Applications

That next stage centered on fake cryptocurrency wallets built to mimic trusted software. Rapid7 recovered counterfeit versions resembling Trezor Suite, Ledger Live, and Exodus, packaged for both macOS and Windows. Once installed, the apps prompted users to type in their 12-to-24-word recovery phrases — the master key to any crypto wallet — which were then exfiltrated straight to the attackers through Telegram. Rapid7 also found the operation hosting a counterfeit Claude Code installer that attempted to quietly install one of these malicious wallet apps alongside the legitimate AI coding tool, blending a trusted developer product with a hidden payload.

How AI Tools Powered the Cryptocurrency Phishing Campaign

What sets Operation ASTERIX apart from older phishing playbooks is the visible role of generative AI in building it. Recovered artifacts from the exposed server show the operators leaning on GitHub Copilot and Claude Code for coding, scripting, application packaging, and infrastructure work — the kind of technical labor that used to demand a dedicated developer.

Use of GitHub Copilot, Claude Code, and AI Tool Switching

Rapid7’s investigation found that the fraudsters used these assistants not just to write functional code but to actively refine it, including attempts to work around the safety guardrails built into the tools themselves.

Efforts to Bypass AI Model Restrictions

At one point, Claude reportedly refused requests tied to code obfuscation. Rather than stopping there, the operator switched to a different model, Kimi, and tried to push past its restrictions as well. Rapid7 says it could not confirm whether that particular bypass attempt succeeded — only that the evidence documents a deliberate pattern of tool-hopping whenever one AI system pushed back.

Why this matters: this pattern shows that AI guardrails, while useful, aren’t a complete barrier when a determined operator simply moves to another model. As AI coding tools multiply, so does the number of doors available to someone trying to slip past safety controls.

Notification, Response, and What Comes Next

Despite the scale of the data involved, the operation’s day-to-day activity looked surprisingly small. Activity logs recovered from the server showed just 20 lead lookups and six phishing emails sent over roughly a two-week window, suggesting the operators favored precision over volume — a small, curated set of high-confidence targets rather than a mass spam run.

Notification to Providers and Authorities

Rapid7 discovered the campaign while much of its infrastructure was still active or under development, and it coordinated with Apple’s security team before publishing its findings on August 17, 2026. The firm also notified other relevant providers about the exposed data and counterfeit applications.

Potential Risks and Exposure for Crypto Users

For exchanges like Crypto.com, the episode raises a pointed question: how much signal do automated account-validation endpoints leak to outside probing? A 13.6% confirmation rate on a phone-number lookup is enough for an attacker to build a workable target list without ever touching a password. That’s a strong argument for tightening how validation APIs respond to bulk queries, since the leak isn’t in the wallet software — it’s in the checkpoint that tells an attacker who’s worth targeting in the first place.

The broader lesson for the industry is less about this one operation and more about what it signals. AI coding assistants have made it faster and cheaper to build convincing fake wallet applications and phishing infrastructure, and Operation ASTERIX shows that guardrails inside those tools can be sidestepped simply by switching to a more permissive model. That combination — cheap AI-assisted development plus large, validated phone datasets — is likely to keep showing up in future cryptocurrency phishing campaigns, whether or not this particular network resurfaces under a new name.

FAQ

What is Operation ASTERIX?

Operation ASTERIX is an AI-powered crypto phishing campaign uncovered by Rapid7 that used phone data, account validation, and fake wallet apps to steal cryptocurrency recovery phrases.

How did attackers identify their targets?

Attackers used extensive phone datasets and automated validation tools to identify phone numbers linked to active cryptocurrency exchange accounts, including over 43,000 Crypto.com accounts identified from a German dataset of 316,002 numbers.

What role did AI tools play in the phishing campaign?

AI coding assistants such as GitHub Copilot and Claude Code were used in coding, scripting, application packaging, and infrastructure tasks for the phishing operation, and operators switched between models after running into safety restrictions.

What steps have been taken after the discovery of Operation ASTERIX?

Rapid7 notified relevant service providers and authorities, including Apple’s security team, and published its findings on August 17, 2026, to help mitigate the campaign.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.