Loading article…
A new crypto phishing campaign, Operation Asterix, has targeted 885,000 phone numbers to steal seed phrases via fake Ledger, Trezor, and Exodus applications.
A large-scale phishing campaign dubbed "Operation Asterix" has targeted approximately 885,000 phone numbers in an attempt to compromise cryptocurrency wallets [1]. The operation uses fraudulent mobile applications masquerading as legitimate services from Ledger, Trezor, and Exodus to harvest user seed phrases and gain unauthorized access to digital assets [1].
| At a glance | |
|---|---|
| Campaign Name | Operation Asterix |
| Target Scope | 885,000 phone numbers |
| Primary Goal | Theft of seed phrases |
| Impersonated Brands | Ledger, Trezor, Exodus |
The campaign relies on social engineering tactics, specifically targeting mobile users with deceptive applications that mimic the interfaces of established hardware and software wallet providers [1]. By convincing users to input their seed phrases—the 12-to-24-word recovery keys that provide full control over a crypto wallet—the attackers aim to drain the associated funds [1].
The scale of this campaign, reaching nearly 900,000 individual phone numbers, highlights a significant increase in the volume of mobile-centric threats facing the crypto ecosystem [1]. Cybersecurity firm Rapid7 identified the campaign, noting that the attackers are specifically leveraging the brand recognition of major industry players to lower the defenses of unsuspecting users [1].
The use of fake applications for Ledger, Trezor, and Exodus suggests a coordinated effort to target both hardware wallet users and those relying on popular software-based storage solutions [1]. Because seed phrases are the master keys to a wallet, any compromise of these credentials typically results in the permanent loss of assets, as transactions on most blockchains are irreversible.
The campaign underscores the persistent risk of mobile-based phishing, where attackers exploit the trust users place in official-looking software downloads [1]. While the total number of compromised accounts remains unclear, the sheer volume of targeted phone numbers indicates a broad-spectrum approach rather than a highly targeted "spear-phishing" strategy [1].
The success of such campaigns often depends on the speed at which users can be directed to malicious download links before security researchers or platform moderators can intervene. Whether this campaign leads to a measurable increase in reported wallet drains remains the primary concern for the broader crypto community.
Coverage is mostly measured — 187 of 189 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 25, 2026 · How we report
Cryptocurrency allows for rapid movement of funds, offers greater anonymity, and often lacks the fraud protections found in traditional banking or credit card transactions.
Warning signs include high-pressure demands for immediate payment, instructions to keep a transaction secret, and unsolicited requests to deposit cash into a cryptocurrency kiosk.
Experts recommend hanging up immediately, refusing to send funds, and independently verifying the caller's identity by contacting the organization directly through a verified phone number.