Rapid7 Operation ASTERIX Shows AI Is Now Core Crypto Phishing Tool
Rapid7 discovered a phishing campaign targeting crypto users, using AI tools to create fake wallet apps and impersonate support. The operation involved 885,000 phone numbers, with a high success rate in identifying CryptoCom accounts. AI tools like GitHub Copilot and Claude Code were used to streamline the process. The campaign highlights the dual-use of AI in both legitimate and malicious activities within the crypto sector.
How this was made

The 30-second read
Why it matters
The report signals a new vector of crypto theft that could pressure wallet providers and exchanges to enhance security protocols.
Market read
New intelligence on AI-facilitated crypto phishing may influence security spending and risk assessments across the crypto ecosystem.
What to watch
Potential regulatory responses and insurance costs for exchanges could amplify market effects.
Background
Operation ASTERIX reveals AI-driven phishing campaigns targeting crypto wallet recovery phrases using counterfeit apps.
Market effects
Highlights rising AI-enabled threats to crypto wallets, may increase security spending in the crypto infrastructure sector.
Primarily affects users and exchanges globally; no immediate regional price impact.
Raises awareness of systemic risk in crypto custody solutions worldwide.
Counterpoint
Some may view the threat as overstated, arguing that most users avoid entering recovery phrases into apps.
Key entities
- companyRapid7
Security firm that uncovered the Operation ASTERIX campaign.
- companyTrezor
Hardware wallet brand whose name was used in counterfeit apps.
- companyLedger
Hardware wallet brand whose name was used in counterfeit apps.
- companyExodus
Software wallet brand whose name was used in counterfeit apps.


