
A misconfigured server exposed a fraud operation with 885K phone numbers, fake Trezor and Ledger apps, and a 13.6% hit rate on Crypto.com accounts. Rapid7 details the attack chain and implications for exchanges.
A misconfigured web server exposed a fraud operation that combined phishing emails, voice calls, and counterfeit wallet applications to steal crypto recovery phrases. Rapid7 Labs documented the scheme and called it Operation ASTERIX.
The exposed directory contained roughly 885,000 phone numbers. The largest batch was 316,002 German mobile numbers. The fraudsters used Asterisk, an open-source telephony platform, to make vishing calls, the researchers said.
On the account validation side, the operation targeted Crypto.com users specifically. The attackers ran automated checks against their database of phone numbers. The hit rate was 13.6%, meaning roughly one in seven numbers corresponded to an active account, Rapid7 found.
Once potential victims were identified, the attack chain moved to personalized email outreach and phone calls. These steered targets toward installing fake wallet applications. The counterfeit apps masqueraded as Trezor Suite and Ledger Live. The bogus software prompted users to enter their 12-to-24-word recovery phrases, which were then exfiltrated via Telegram.
Rapid7's investigation also found evidence that the fraudsters used GitHub Copilot to write and refine their malicious code. The researchers noted attempts to bypass security safeguards built into the AI assistant itself.
Activity logs recovered from the server showed only 20 lead lookups and 6 phishing emails sent over an approximately two-week period.
Rapid7 coordinated with Apple Security to disclose their findings. The report was published on August 17, 2026.
The 13.6% hit rate on Crypto.com account validation is a useful data point for understanding the scale of exposure. If the fraudsters ran that same check against their full database of 885,000 numbers, they would potentially identify more than 120,000 active exchange users to target, the researchers said.
For exchanges like Crypto.com that were specifically targeted, the exposure raises questions about how account validation endpoints can be hardened against automated probing. A 13.6% confirmation rate means the API or lookup mechanism was returning enough signal for attackers to build a reliable target list, Rapid7 said.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.