Rapid7 Labs uncovered Operation ASTERIX, a crypto fraud pipeline that leveraged AI coding assistants to create fake Ledger, Trezor, and Exodus apps.
It matched 43,066 phone numbers to actual exchange accounts. Any user who self-custodies their crypto is a potential target. The operation was still ongoing when researchers discovered it.
A misconfigured server gave up the whole playbook
An exposed web directory was discovered by Rapid7 researchers Anna Širokova and Jan Recinsky on campaign infrastructure. Inside were the raw ingredients of a live fraud operation.
The pair’s August 17 report detailed the data trove, which included phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, the fake wallet applications themselves, and code to siphon stolen data out through Telegram.
Most of that tooling was still in use or in development when it leaked. Rapid7 said it could reach out to providers and authorities, including Apple’s security team, while the campaign was happening.
The operation is named after Asterisk, the open-source telephony platform recovered on the server. The operator used Asterisk to make the vishing, or voice-phishing, calls to coincide with fake support emails victims had already received.
In the open directory there were around 885,000 phone numbers, and the largest file was a collection of 316,002 German mobile numbers. Smaller directories included Hong Kong, Bulgaria, the UK, the US, Canadian fintech customers, and Ledger-related lists.
The operators then checked those German numbers against an account checker and confirmed that 43,066 were crypto exchange users. This is a hit rate of about 13.6%, almost one in seven.
A further batch of 5,576 numbers was associated with Binance accounts and lined up for attack. The report also mentioned a Kraken checker and fake emails pretending to be from Crypto.com.
The count of validated targets sits oddly against the activity logs. The logs recovered indicate that there were only 20 lead lookups during a span of about two weeks.
Additionally, six phishing emails were sent, suggesting that the operators favored a slow, hand-selected targeting approach rather than contacting all numbers.
The fake apps asked for a seed phrase
The apps mimic Trezor Suite and Ledger Live, with Exodus also spoofed, and they ask users to enter a recovery phrase of 12 to 24 words that controls a hardware wallet.
That phrase is the master key to the funds, and whoever has it can empty the wallet. The stolen phrases were then exfiltrated via Telegram.
Rapid7 found that AI coding assistants were used across the entire development process, not just to spit out isolated snippets.
Recovered prompts, shell history, and project files show the operator relying on AI tools to package the Electron apps, obfuscate code, fix builds, and prepare the malware for distribution.
The tool was GitHub Copilot. When one model began to refuse parts of the work, the operator switched providers and attempted to break the next model’s safety controls with a custom jailbreak prompt, Rapid7 said.
Earlier in August, Trezor warned 13,689 customers after a breach at its shipping partner ShipMonk exposed names, emails, phone numbers, and addresses, as Cryptopolitan reported.
Ledger and Trezor owners have also received physical letters with QR codes leading to phishing sites, as Cryptopolitan reported back in February.
Hacken, a blockchain security firm, said that phishing and social engineering made up $306 million of the crypto industry’s $482 million in first-quarter losses.