Loading market data...
Back to Feed
CRYPTO NEWS

Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbers

Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for Cybersecurity firm unveils crypto phishing campaign targeting 885,000 phone numbers
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$306 million$482 million

Summary

Cybersecurity firm Rapid7 revealed a cryptocurrency phishing campaign called Operation Asterix, targeting approximately 885,000 phone numbers across multiple countries to steal crypto investors' assets. The campaign involved fake apps impersonating Ledger, Trezor, and Exodus wallets and used phishing emails pretending to be from Crypto.com. Analysts reported that 5,576 Binance accounts were queued for attack, with a "hit rate" of about 13.6% based on validated matches from the German dataset.

Why it matters

Rapid7 highlights that phishing attacks and social engineering scams caused the majority of crypto industry losses in Q1 2024, amounting to $306 million out of $482 million total lost. The use of fake apps and AI tools in this campaign underscores ongoing vulnerabilities in user security and highlights the persistent risk phishing poses to crypto investors.

Key context

The campaign targeted mobile numbers mainly in Germany but also included Hong Kong, Bulgaria, the UK, the US, and Canada. Attackers used fake support communications and apps to steal seed phrases. Previous incidents referenced include a Trezor data breach via ShipMonk and scams involving phishing token approvals and fake Ledger Live apps, demonstrating a trend of increasingly sophisticated phishing tactics in crypto.

Key numbers and entities

Entities involved include Rapid7, Binance, Crypto.com, Ledger, Trezor, Exodus, and Kraken. The campaign targeted 885,000 phone numbers, including 316,002 German numbers. 5,576 Binance accounts were targeted, and 43,066 accounts were validated from the German dataset. Losses from phishing and scams were reported at $306 million in Q1 2024, per blockchain security company Hacken.

What remains unclear

Details on how targets were filtered, specific vulnerabilities exploited in hardware wallet spoofing, and the full role of AI in the phishing attacks remain undisclosed. Rapid7 analysts have not yet commented further on these technical details, pending their response to Cointelegraph’s inquiry.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]