Crypto Phishing Ring ‘Operation Asterix’ Targeted 885,000 Phone Numbers, Queued 5,576 Binance Accounts

Roughly 885,000 phone numbers. That is the scale of the target list cybersecurity firm Rapid7 says it recovered from an exposed server tied to a cryptocurrency phishing operation it has named Operation Asterix. The numbers were not scraped at random — logs show they were run through automated validation checks designed to confirm which ones belonged to real exchange accounts before attackers ever made contact.
Here is what the recovered data showed, according to Rapid7’s findings:
- 885,000 phone numbers pulled together from multiple countries, organized into files by geography and source.
- 316,002 German mobile numbers in the single largest file, alongside separate lists covering Hong Kong, Bulgaria, the UK, the US, Canadian fintech users, and Ledger-related contacts.
- 5,576 accounts confirmed to match real users on Binance, all queued up for targeted attack.
- 13.6% hit rate when a batch of numbers was checked against Crypto.com accounts — a rate that, applied across the full 885,000-number database, could theoretically flag well over 100,000 active exchange users.
- Fake support emails impersonating Crypto.com, used to build trust before the real ask.
The name Asterix comes from Asterisk, the open-source phone system Rapid7 found running on the exposed infrastructure — the same software that let the operators automate voice-phishing calls, or “vishing,” and tie them together with fraudulent emails and counterfeit wallet software. One fake Trezor app identified in the investigation was built to detect and shut down the real Trezor software on a victim’s device, then pop up a lookalike screen asking for a 12-, 18-, 20-, or 24-word recovery phrase. A separate fake Ledger app followed a similar script. Once entered, that phrase — along with the victim’s passphrase and IP address — was funneled out through Telegram.
Rapid7 also flagged something newer: signs that AI coding tools had become part of the attackers’ own workflow, used to package the fake Electron-based wallet apps, debug builds, tweak the phishing infrastructure, and obfuscate the malicious code so it would slip past detection.
None of this required a single software exploit. Every step relies on a victim being convinced to act — answering a call that looks legitimate, opening an email that appears to come from a real exchange, or typing a seed phrase into an app that looks like the real thing. That is precisely why campaigns like this scale so easily: a validated phone number is worth far more to an attacker than a random one, and a list of hundreds of thousands lets a crew work through targets methodically rather than casting a blind net.
For anyone holding crypto, the practical takeaway does not change with each new campaign name: no legitimate exchange, wallet maker, or support team will ever ask for a seed phrase over the phone, by email, or inside an app. A recovery phrase typed anywhere other than the wallet that generated it should be treated as compromised the moment it happens.
Crypto assets are volatile and carry the risk of total loss, including through scams and phishing attacks like the one described above. This article is for informational purposes only and is not financial or security advice. Always verify wallet software through official sources and never share a seed phrase with anyone. For a primer on safely storing and securing digital assets, see coin680’s Bitcoin Academy.
