885,000 phone numbers leaked: Are crypto wallets in danger?

A new phishing campaign in the crypto sector has targeted approximately 885,000 phone numbers. Can an innocent message arriving on your mobile lead to access to your digital wallet?

ICEAuthor: Yosef Dolgopolsky
Source
885,000 phone numbers leaked: Are crypto wallets in danger?
Photo: ICE / קריפטו בירידה (צילום shutterstock)

Cybersecurity company Rapid7 has uncovered a large-scale phishing campaign called Operation Asterix, which was based on a database of approximately 885,000 phone numbers and was designed to identify users holding crypto accounts.

According to the company's findings, the attackers did not settle for sending random messages: they tried to check which phone numbers were linked to accounts on crypto platforms, and then focus on individuals with a higher probability of being compromised. Among other things, thousands of targets were identified as being linked to users of the Binance exchange.

The next stage of the operation was impersonation. The attackers used fake applications that posed as well-known wallet services, including Ledger, Trezor, and Exodus, alongside emails and phone calls that pretended to be customer support. The goal was to get the victim to provide their recovery phrase, the sequence of words that allows access to the crypto wallet.

In the crypto world, handing over the recovery phrase to a foreign party could allow them to take control of the assets, and therefore it is one of the most sensitive details a user can possess. According to reports on Rapid7's findings, the campaign also used automated tools and components that appear to have been developed or accelerated with the help of AI (artificial intelligence) tools, which allows for expanding such attacks and making them more targeted.

This story highlights a significant shift in the world of fraud: the attacker no longer has to hack directly into a wallet or break an encryption system. Sometimes the simpler way is to reach the user themselves, through a message that looks reliable or a phone call from a person who introduces themselves as a support representative. When the inquiry includes the name of the company where the user holds an account, and sometimes other personal details, it is easier to create a sense of reliability and cause the victim to act quickly. This is exactly why targeted campaigns are considered more dangerous than regular spam messages: instead of trying to defraud millions of people blindly, the attackers first try to identify which of them is a crypto user.

For crypto holders in Israel and around the world, the golden rule remains simple: never give the recovery phrase or the private key to another person, even if the inquiry looks like it came from Binance, Ledger, Trezor, Exodus, or any other well-known company.

In the case of a suspicious message or call, it is better to end the inquiry and enter the official website or application independently. The aforementioned Operation Asterix proves that the question is no longer just whether someone will try to defraud crypto users, but how accurate the information is in the attacker's possession when they decide to choose the next victim.

Related News