Operation Asterix crypto phishing targets 885,000 phone numbers to steal wallets

Cybersecurity firm Rapid7 reported a large-scale crypto phishing campaign, “Operation Asterix,” targeting about 885,000 phone numbers across multiple countries. The goal of the phishing operation is to redirect victims to fake wallet provider websites and steal cryptocurrency holdings. Key findings include: - 5,576 accounts matched to Binance users were queued for attack. - The largest dataset contained 316,002 German mobile numbers, with additional lists covering regions such as Hong Kong, Bulgaria, the UK, the US and Canada, plus Ledger-related directories. - The campaign used phishing links to push victims toward fake apps impersonating Ledger, Trezor and Exodus, aiming to capture seed phrases. - Attackers reached out via fake support emails and phone inquiries, while Rapid7 also found artifacts indicating AI-assisted components. Rapid7 estimated a “hit rate” of ~13.6% by matching 43,066 accounts using exchange data (validated against the larger German dataset). The report also identified a checker for Kraken to bulk-validate phone numbers against exchange accounts. Industry context: phishing and social engineering scams accounted for $306 million of $482 million crypto losses in the first quarter (per Hacken). The article notes prior incidents where malicious approvals, fake wallet apps, and phishing ads (including Uniswap impersonation) led to large thefts. For traders, this is a reminder that phishing risk continues to drive real losses and can quickly disrupt sentiment, especially around self-custody wallets and exchange user accounts.
Bearish
This news is likely bearish because it highlights an active, high-scale crypto phishing campaign with measurable targeting (885,000 phone numbers, ~13.6% hit rate, and 5,576 Binance-linked accounts queued). Direct theft of funds tends to worsen trader sentiment and can increase perceived smart-adjacent risk around exchanges, wallet providers, and user verification flows. In the short term, traders may see heightened caution around self-custody behavior (seed phrase handling, wallet app authenticity) and around account hygiene for centralized exchanges. Historically, large phishing reports often lead to temporary risk-off positioning in the affected user segments and can cause short-lived volatility driven by fear of more headlines and potential downstream operational issues. In the long term, the market impact can normalize once users shift to better defenses (hardware-wallet authenticity checks, tighter app sourcing, MFA, and rapid incident response). However, repeated phishing clusters keep a persistent overhang on confidence, especially during periods when volatility is already high.