Cybersecurity firm Rapid7 has disclosed the workings of Operation ASTERIX, a cryptocurrency fraud pipeline that combined phone number scraping, phishing, voice calls and counterfeit wallet software to steal victims' seed phrases. According to Rapid7's research report, the operator processed roughly 885,000 phone numbers pulled from regional datasets, including a list of 316,002 German mobile numbers, before validating which ones belonged to actual crypto exchange accounts. Against Crypto.com alone, that validation step returned a 13.6% hit rate, confirming more than 43,000 real accounts from the German list.
Rather than blasting phishing messages at random, the operator built a targeted pipeline: enumerate phone numbers, validate exchange membership, enrich the confirmed hits with names and account details, then move to phishing emails impersonating support staff from Crypto.com and Binance. Victims who engaged were sent fake verification codes and followed up with vishing calls that referenced their real account details to sound legitimate, before being directed to install a counterfeit wallet app to "verify" their holdings.
Fake Wallets Built to Fool Real Ones
Rapid7 recovered counterfeit builds impersonating Trezor Suite, Ledger Live and Exodus. The Trezor fake was the most developed: it ran a hidden, pixel-sized Electron window that scanned every five seconds for the genuine Trezor Suite app, killed it on detection, and swapped in the counterfeit interface in its place, then exfiltrated captured 12-to-24-word recovery phrases straight to Telegram.
Related: FBI May Have Identified First-Wave Attacker in $116M Coldcard Theft
The Ledger impersonation added clipboard hijacking on Windows, while the Exodus version relied on a trojanized JavaScript file to deliver its payload. Activity logs suggested this was a relatively small, operator-led campaign rather than a mass blast — one panel recorded just 20 lead lookups and six phishing emails across two weeks.
How AI Tools Were Used — and Where One Pushed Back
Rapid7's report also details how the operator leaned on AI coding assistants throughout development, using GitHub Copilot for backend scaffolding and Claude Code to manage and format the phone number datasets. When the operator tried to get Claude to help obfuscate the malicious code, the model declined, and the operator switched to a different AI system, Kimi, submitting a jailbreak-style prompt designed to strip away the model's safety behavior before it would comply. Rapid7 said the operator's heavy reliance on AI assistants throughout, rather than in-house tooling, points to a technically capable but not especially sophisticated actor.
Why This Case Stands Out
Hardware-wallet impersonation scams aren't new, but they carry outsized stakes: a single Trezor-impersonation phishing case in January 2026 cost one investor $284 million after they were manipulated into handing over a recovery seed phrase. Rapid7 said it disclosed its findings to Apple and relevant authorities while the operation was still active, and the recovered indicators — including specific command-and-control IP addresses and lookalike domains such as ledger[.]com[.]lv — give defenders a concrete way to spot related infrastructure going forward.