📅 Rabu, 26 Agustus 2026 · --:-- WIB Ikuti kami
Ecosystem
ID
Operation Asterix Incar 885.000 Nomor Telepon Global - 5.576 Pengguna Binance Masuk Antrean Serangan

Operation Asterix Targets 885,000 Global Phone Numbers - 5,576 Binance Users in Attack Queue

Cybersecurity firm Rapid7 has recently uncovered a large-scale crypto phishing campaign dubbed Operation Asterix. The campaign targets 885,000 victim phone numbers from various countries. According to Rapid7 analysts Anna Sirokova and Jan Recinsky, the attackers manage a complex database to store targets’ personal information. The largest file in the database contains 316,002 mobile phone numbers belonging to German citizens. Other data directories include number lists from Hong Kong, Bulgaria, the United Kingdom, the United States, several Canadian fintech companies, and contact lists specifically linked to Ledger crypto wallet users.

All this data is not left idle; attackers are actively using it as raw material for online identity screening.

How AI Accelerates the Hunt for Victims

The target selection process in Operation Asterix has a clear direction. In the case of the German dataset, the attackers matched 43,066 accounts with crypto exchange user profiles - showing a match rate, or hit rate, of 13.6 percent. This identification process ran quickly because the attackers deployed artificial intelligence (AI) tools as a key operational component. They also used automated check tools, or checkers, specifically designed for the Kraken platform to validate phone numbers at scale.

Once a victim’s crypto identity is verified, their phone number immediately goes on the attack radar. Rapid7’s log findings show that 5,576 accounts were matched specifically with active Binance users. These thousands of accounts have officially entered the attacker’s execution queue. Beyond phone attacks, the attackers are also casting a wider net by distributing fake emails posing as the official services of the Crypto.com exchange.

Stealing Seed Phrases Through Replica Interfaces

Once targets are on the queue list, the attackers begin executing social engineering. They contact potential victims through fake customer support emails and phone calls designed to look official. Through these communications, the attackers build a narrative directing victims to immediately download additional security software.

In reality, the software is a trap. This fraudulent application mimics the exact interface of various popular crypto wallets, including Ledger, Trezor, and Exodus. Once victims type their seed phrases into the fields of this fake app, control of their assets transfers to the attackers within seconds.

Leaked user data streams are indeed often the starting point for this kind of phishing campaign. For context, hardware wallet manufacturer Trezor previously reported a data breach incident that exposed the information of 14,000 users. This leak stemmed from a vulnerability at a third-party shipping service provider, ShipMonk.

Such cascading incidents have a real impact on the industry. According to a security report from Hacken, phishing and social engineering attacks dominated the root causes of digital asset losses during the first quarter of this year. The figure exceeded $306 million, accounting for the majority of the $482 million in global crypto losses.

For those of you who store crypto in self-custodial wallets, the Asterix tactic underscores one standard procedure: any instruction via a phone call urging you to enter your recovery phrase into a new link is not an exchange procedure - that is where the theft of your assets begins.

As reported by Cointelegraph.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Bagikan artikel ini:
📩 KABAR BITCOIN 1 MENIT

Berita kripto harian, langsung ke inbox

Ringkasan 1 menit untuk kamu yang selalu bergerak. Gratis, kapan saja bisa berhenti.

Total
0
Share