AI-powered crypto phishing operation exposed 885,000 phone numbers, Rapid7 finds

A misconfigured web server has pulled back the curtain on one of the more calculated AI-powered crypto phishing operations security researchers have documented this year. Cybersecurity firm Rapid7 says it stumbled onto the exposed infrastructure almost by accident, and what it found inside was a fully built fraud machine: nearly 900,000 phone numbers, automated account-checking tools, counterfeit wallet software, and code written with the help of mainstream AI coding assistants. Rapid7 has named the campaign Operation ASTERIX, and it offers a rare, detailed look at how generative AI tools are being folded into cryptocurrency phishing campaigns that once required far more manual effort to run.
Key takeaways
- Rapid7 uncovered Operation ASTERIX, an AI-powered crypto phishing campaign, after finding a misconfigured, exposed server.
- The exposed dataset held roughly 885,000 phone numbers, including 316,002 German mobile numbers, and produced 43,066 matched Crypto.com accounts.
- Attackers built fake wallet apps mimicking Trezor Suite, Ledger Live, and Exodus, alongside phishing pages spoofing Crypto.com and Binance.
- Coding assistants GitHub Copilot and Claude Code were used to write, package, and refine the malicious tools, and operators tried switching AI models after hitting safety restrictions.
- Rapid7 notified affected providers and authorities, including Apple’s security team, after documenting the operation.
Rapid7 Uncovers Operation ASTERIX and Its Real Scale
Operation ASTERIX combined phishing emails, voice calls, and fake wallet software into a single, coordinated fraud pipeline, and the numbers behind it are striking. Rapid7’s exposed directory contained approximately 885,000 phone numbers spread across multiple datasets, each one apparently gathered to feed the operation’s targeting engine.
… Continue reading the full article at the original source below.

