Counterfeit wallet apps are not a new threat, but Operation ASTERIX shows how much more precise these schemes have become. Rapid7 uncovered a campaign built around roughly 885,000 phone numbers, crypto account-validation tools, phishing emails, vishing calls, and fake Trezor, Ledger, and Exodus apps designed to capture recovery phrases, according to the original report .
The most striking detail is not the volume of phone numbers. It is the validation layer. In one German dataset, operators identified 43,066 CryptoCom accounts from 316,002 phone numbers. That is a hit rate high enough to justify the infrastructure. After confirming which numbers were tied to exchange accounts, the group enriched those targets with personal details, making support impersonation calls much harder to detect. A public list of phone numbers is a nuisance; a list that has been cross-checked against exchange account data is an operational asset.
AI tools compressed the production cycle
Rapid7 found signs that the operators used GitHub Copilot and Claude Code across multiple stages of the campaign. Those tools were applied to process target data, develop and debug malicious software, and build phishing infrastructure. That matters because it shrinks the distance between target discovery and an active fake wallet app or phone scam. Tasks that once required a dedicated developer can now be handled by smaller crews using AI coding assistants.
The sector’s broader AI adoption is not limited to hostile actors. Rankings of Top 10 Blockchains by Developer Activity This Week track code contributions across major chains, and those workflows increasingly include AI-assisted development. The same productivity gains that help legitimate teams ship faster also make malicious wallet apps easier to produce, which is precisely the dual-use problem Operation ASTERIX exposes. AI tooling now runs through legitimate Web3 infrastructure too, including scalable AI-driven Web3 applications .
The jailbreak question remains open
One interaction stands out. When Claude refused requests related to code obfuscation, the operator switched to Kimi and attempted to bypass its safety controls with a custom jailbreak prompt. Rapid7 could not confirm whether the attempt succeeded. That uncertainty is relevant because it separates a simple misuse of general-purpose tools from a more deliberate effort to defeat model restrictions. The former is a moderation gap; the latter is a red-team exercise run by criminals.
Without confirmation, the report avoids overstating the jailbreak result. It does, however, confirm that the campaign treated AI model refusals as an obstacle to route around rather than a reason to stop. Security researchers and platform providers will likely scrutinize that behavior when deciding how aggressively to restrict coding assistance around wallet-related software.
What users and platforms should watch
The counterfeit apps named in the report target the same recovery phrase users are told never to enter anywhere. Fake Trezor, Ledger, and Exodus apps create a direct path from a convincing interface to a drained wallet. That is why download source matters more than app appearance. Official hardware wallet vendors do not ask users to enter recovery phrases into software, and exchange support lines do not call customers with a full personal profile already loaded.
The operation also sharpens a hard truth for exchanges. If account validation is cheap enough to run against hundreds of thousands of numbers, then user data leaks and public breach corpora become a higher-value input for vishing campaigns. The report does not allege an exchange breach; it shows how seemingly thin data can be enriched into actionable targeting information.
Lawmakers weighing crypto market structure rules may find this kind of disclosure hard to ignore. Banking groups have already been pressing against the biggest crypto bill in US history , and cybercrime incidents involving retail wallets could sharpen the debate over liability, consumer protection, and platform responsibility. Whether Operation ASTERIX becomes a regulatory data point depends on how quickly similar campaigns are detected elsewhere.