Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If someone calls you, knows your name and your email address and asks you to reinstall a wallet application, then the call is in all likelihood the attack itself. That is exactly the pattern the security firm Rapid7 describes in a report dated August 17, 2026, under the name Operation ASTERIX. The core of it for readers in Germany sits in a single figure: the largest file secured held 316,002 German mobile numbers.
The case is notable because it wires together three attack routes that usually appear separately. A phone system dials automatically. An email supplies the pretext. And at the end sits a program that looks like the familiar wallet software and asks for the recovery words. Once you have understood this chain, you can spot it at the point where it breaks.
Operation ASTERIX Explained: What Rapid7 Found on an Open Server
Operation ASTERIX is the name for a fraud chain that combines phone calls, phishing emails and counterfeit wallet programs into a single sequence. The analysts assigned the name themselves: the server was running Asterisk, an open-source phone system, and that formed the backbone of the calls.
The server was found because its operators made a mistake. According to Rapid7, a web directory on port 8080 was reachable without any login and listed its contents openly. Inside were phone number datasets, account-checking tools, ready-made installation packages for the counterfeit programs, phishing interfaces, dialling scripts and session logs from the language models in use. Rapid7 says it reported the findings to Apple's security team among others and worked with those involved on countermeasures.
A find of this completeness is rare. Usually you see only the part of a campaign that reaches the victim. Here the workbench lay open.
316,002 German Mobile Numbers: Why Germany Was the Largest Single Item
In total the datasets found covered around 885,000 phone numbers from several regions. Alongside Germany, the report names Hong Kong, Bulgaria, the United Kingdom, the United States and a Canadian financial services provider. For users of one well-known hardware wallet brand there were an additional 54 files sorted by country.
The German file was the largest single one. That does not mean 316,002 people in Germany were called. It means their numbers were on hand as a starting pool. The distinction matters and is picked up again further down, because it determines how large this campaign actually was.
Where the numbers came from, the report does not say. Datasets of this order have been circulating for years from data breaches at retailers, shipping providers and online services. For your defences the origin is irrelevant: a phone number cannot be recalled.
A 13.6 Percent Hit Rate: How Crypto Accounts Are Filtered Out of Phone Numbers
The real trick happens before the first call. The operators ran automated checking tools against the login function of a large trading venue and established in that way which number holds an account there. The method exploits the fact that many services answer a login attempt differently depending on whether a number is registered.
According to the figures in the report, the hit rate in the German dataset was 13.6 percent. That turned the 316,002 numbers into 43,066 confirmed accounts. Roughly every seventh number belonged to an active user.
For the attackers this is a question of efficiency. Instead of calling hundreds of thousands of people and meeting blank incomprehension from most of them, they are left with a list on which everyone called knows the product being discussed. That makes the call plausible before a single word has been spoken.
Vishing Instead of Email: How the Call Is Placed Through a Phone System
Vishing means phishing by voice call: the fraud attempt runs over the telephone rather than by email. On the server Rapid7 found the full kit for it, including the Asterisk and 3CX phone systems as well as several scripts for automated dialling and for coordination with the rest of the infrastructure.
The effect comes from the preparation. Whoever calls can, according to the report, state the name of the person called, the email address, the location and details about the account. That is not magic but the result of the upstream check and the datasets. To the person called it looks like a call back from the provider, with the staff member holding the file.
Then comes the pretext. There is a security problem, a suspicious login, a necessary update. The solution offered is always the same: install an application, available by email or through a link that is named.
Counterfeit Trezor Suite, Ledger Live and Exodus: Which Wallet Programs Were Cloned
Rapid7 secured three counterfeit applications. They are fakes of Trezor Suite, Ledger Live and Exodus, each as an installation package for Windows and macOS, and in the case of the Trezor fake separately for Intel and Arm processors.
The point often misunderstood here: the makers of these programs are the ones being impersonated in this case. Neither their devices nor their genuine applications were attacked. What was cloned is the interface, meaning what you see on the screen. The attack takes place at the moment you type your words into a window that merely looks like the familiar one.

The Double Entry Trick: Why the Fake App Fakes an Error
The most interesting detail in the report is a small piece of nastiness in the sequence. The counterfeit Trezor application accepts recovery phrases of 12, 18, 20 or 24 words, plus an additional passphrase on request. After the first entry it displays an invented validation error and asks for the words again.
This serves the perpetrators' quality control. Anyone typing out a recovery phrase makes typing errors easily, and a single wrong word makes the haul worthless. The faked error ensures that the second entry is made more carefully and that both versions can be compared.
If you know this behaviour, you have a very clear warning sign to hand. A genuine wallet application does not ask you to enter your recovery words during normal operation. Those words are needed only when setting up a device or restoring it after a loss, and then on the device itself.
Hardware Wallets ComparedSeed Phrase via Telegram Bot: Where the Recovery Words Drain Away To
The seed phrase, also called the recovery phrase, is the sequence of words from which all of a wallet's keys can be recalculated. Whoever holds it holds the balance, regardless of where the device happens to be.
According to Rapid7's analysis, the counterfeit application packs the word sequence, the optional passphrase and the computer's IP address into a single message and sends it to a Telegram bot. The message carries a header naming its contents. The exfiltration is therefore organised immediately and without the detour of the attackers' own server.
In practice that means: between the entry and the attackers' access lie seconds, not hours. There is no way to revoke it. How to store a recovery phrase instead, without ever typing it into a text field, we have described in a separate article on storing your seed phrase safely.
Trojanised Installer: How a Fake Tool Ships the Wrong Wallet With It
One find falls outside the usual pattern. Alongside the three wallet fakes, the server held a manipulated installation program that passes itself off as a developer tool while shipping the counterfeit Ledger Live application with it.
That shifts the target group. Those addressed are no longer only investors reacting to a support call, but also technically adept users who download software from search results or advertisements. This group in particular considers itself less at risk, because it recognises the classic phishing emails.
For you that yields a simple rule, made concrete in the section on sources further down: an installation package is only as trustworthy as the route by which you obtained it.
AI Tools in the Attack Kit: What the Session Logs Show
Because the operators left their working environment lying open, the logs of their language model sessions have survived as well. Rapid7 describes the tools as having been used for ordinary developer work: writing scripts, preparing data, packaging applications, setting up infrastructure.
The report assigns the tasks to different providers. A programming assistant is said to have helped with development in the background, and a further tool with managing and cleaning the number lists, among them a holding of more than 103,000 Polish phone numbers. When it came to obfuscating malicious code, the request was refused, whereupon the operators switched to another model and attempted a workaround there. Whether that attempt succeeded cannot be established, according to Rapid7.
For context it matters what is proven here and what is not. What is proven is that the attackers used such tools for preparation. What is not proven is that these tools were what made the attack possible in the first place. Phone systems, number lists and cloned interfaces existed long before; the logs mainly show how much effort falls away when routine work is handed to a machine.

Only 20 Queries and Six Emails: Why the Campaign Was Smaller Than the Numbers Suggest
At this point a figure belongs in the text that contradicts the headline. In one of the phishing interfaces, according to Rapid7, only 20 successful data queries and six phishing emails sent were logged over a period of around two weeks.
That is not a mass mailing. It points to a campaign under construction, or to a deliberately small, targeted selection. The 885,000 numbers therefore describe the potential of the stock, not the number of people affected. Anyone turning that into a report about hundreds of thousands of harmed investors is overstating the finding.
The relevance for you does not change much because of it, though. The blueprint is documented, the tools are assembled, and the preparatory work in the form of checked account lists has been done. Infrastructure like this is rarely shut down; it changes operator.
A Fake Support Call: How to Recognise One During the Conversation
There are a handful of markers that hold regardless of the provider and that you can memorise for the moment it matters.
- Nobody calls you whom you have not called. Trading venues and wallet manufacturers work through ticket systems, not through outbound calls to private customers.
- The caller knows your details. That is no proof of authenticity but, after this case, rather a warning sign, because checked lists are the starting point.
- Time pressure builds. An access supposedly under way, a block within minutes, an update that has to happen immediately.
- At the end there is always an installation or an entry. That is precisely the purpose of the conversation.
- The call-back route is circumvented. Anyone genuine has no objection to you hanging up and getting in touch yourself via the official address.
The last point is the most robust. Hang up, find your provider's contact page through your own browser history or bookmark, and ask there. A genuine matter survives a call back; a fraud attempt does not.
The same basic rule applies to the email variant of the scam, in which a supposed withdrawal request lands in your inbox. How to recognise that is set out in our article on counterfeit withdrawal requests.
Regulated Crypto Exchanges ComparedChecking a Wallet App: Where the Genuine Programs Actually Sit
Because three well-known applications were cloned in this case, the routes by which they are obtained are worth a look. We called up the obvious addresses ourselves on August 22, 2026 at around 19:00 UTC, to see where a user actually lands.
The result is inconsistent. The official page for Trezor Suite answered directly and led to the program. The obvious address for Ledger Live, by contrast, redirected to the manufacturer's shop area, so not to a pure download page. With Exodus the automated call to the download address was refused, while the main page answered normally. That refusal is a protection mechanism against bots and says nothing about reachability in a browser.
Where to Get Wallet Software: What That Means for You in Practice
If even the direct route to the manufacturer redirects, the likelihood is high that users will search instead. And search results and paid advertisements have for years been the most convenient distribution route for cloned applications. So set a bookmark to the manufacturer's page while you have reached it safely, and use only that from then on. If you are facing the choice of a device, you will find the providers together with their official sources in our hardware wallet comparison.
Seed Phrase Entered: What Counts in the First Few Minutes
If you have typed a recovery phrase into a program whose origin you cannot establish with certainty, the wallet counts as compromised. Not as possibly at risk, but as open.
The order of steps is then unambiguous. On a device you trust, set up a new wallet with a new recovery phrase. Transfer the balance there, starting with the largest holding. Only after that check what else might be affected, such as identical passwords or linked accounts at trading venues. Changing a wallet's password does not help at this point, because the words themselves are the access.
Document the process in parallel: time, application, origin of the file, transaction identifiers. You will need these details for a police report and for the later tax treatment of a loss, and after the fact they are hard to reconstruct.
Spotting a Fake Wallet App: What to Take Away
- Treat every unsolicited call about your crypto account as a fraud attempt. Hang up and get in touch by a route you know yourself. If in doing so you discover that your provider runs no telephone support at all, you already have your answer. Which trading venues are authorised in the EU and how to find their genuine contact routes is shown in our overview of regulated crypto exchanges.
- Obtain wallet software exclusively through a bookmark you have set yourself. Not through search hits, not through advertisements, not through a link from a conversation. An overview of the common applications together with manufacturer details is in the software wallet comparison.
- Do not enter your recovery phrase into any program that asks for it during normal operation. Those words belong on the device when setting up or restoring, and nowhere else. Which device confirms the entry on its own display and thereby secures the decisive intermediate step is set out in the hardware wallet comparison.
The report itself is publicly available and is the basis for all the details in this article: Rapid7 Labs on Operation ASTERIX.
(As of August 22, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
- Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
- D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
- Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
September 15, 2026 10:14 PM

AI Crypto Crime: How Scams Are Getting More Convincing
AI is sharpening fake support, deepfakes and phishing across the crypto space. Why the data still needs a careful reading and which security routines protect a wallet.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
September 26, 2026 4:21 AM

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls
Six authorities have disconnected 13,888 phone numbers used by investment fraudsters to call their victims in Operation Herakles, 9,304 of them in the past three months alone. What the Federal Network Agency now requires of telecoms providers and which three checks protect you from the scheme.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 5, 2026 10:24 PM

Fake German Finance Ministry Letters: Why Nobody May Demand 19 Percent VAT on Your Crypto Purchase
Since September 1, 2026, Germany's Federal Ministry of Finance has been warning about forged letters that demand 19 percent VAT on cryptocurrency purchases while citing real transactions. That tax does not exist, and this is how to spot the forgery.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
August 31, 2026 10:12 AM

Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
Fraudulent websites pose as money-laundering screening services for crypto addresses and ask you to connect your wallet. A genuine check needs only the public address, and three of the domains named by Malwarebytes still respond twelve days later.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 23, 2026 1:16 PM

Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
A fake wallet address matched the real one in just seven of forty characters and still intercepted 2 million USDC. Our own count of the affected wallet shows that a third of all counterparties in its history belong to such look-alikes.
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
January 22, 2025 11:31 AM

How to Identify Fake TRUMP tokens: A Guide to Staying Safe in the Crypto World
The rise of fake TRUMP and MELANIA tokens is alarming crypto enthusiasts. Learn how to distinguish the official tokens from scams and protect your investments with this essential guide.
September 16, 2026 4:12 AM

Wallet Drops a Network: How to Rescue Your Coins Before the Deadline
Phantom is ending Sui support on September 24, 2026, and Trust Wallet has already removed 25 networks: five shutdowns of this kind in four weeks alone. What really happens to your balance, which two routes you have before the deadline and where the move most often fails.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
August 22, 2026 4:16 PM

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
September 14, 2026 1:27 PM

Bitcoin Lost to a Scam: What Counts as a Tax Loss in Austria
Lost bitcoin to a scam? Why Austria generally does not recognise the damage as a tax loss for privately held assets, and when compensation payments start to matter.
August 22, 2026 10:13 AM

BaFin Warns Against NC Wallet and ncwallet.net: What Users of the Wallet App Must Check Now
On August 19, 2026, BaFin issued a warning about the NC Wallet app and two websites: on the regulator's findings, the unknown operators offer financial services there without authorisation. Because the wallet is custodial, it is the provider and not you who holds the key to your balance.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
August 18, 2026 7:23 PM

Inheriting Crypto: How Your Heirs Actually Get Access, and Why the Seed Does Not Belong in a Will
The German Federal Court of Justice made clear in 2018 that digital accounts are inherited like everything else. With self-custodied coins succession law still achieves nothing: no key, no access. And anyone who writes the seed into a will has a court send it to every party involved.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
More from CryptoTicker
