Cybersecurity firm Rapid7 has disclosed a cryptocurrency phishing operation it calls Operation Asterix, uncovered after researchers found a misconfigured web server holding target data and attack tooling. Two independently reported accounts of the disclosure — from Cointelegraph and Crypto Briefing — agree on the scale of the exposed dataset and the mechanics of the scheme, but diverge on which exchanges were named as targets, how the disclosure to Apple was handled, and how much day-to-day activity the operation actually generated.
According to Cointelegraph, Rapid7 unveiled the campaign in a report published Monday, describing it as targeting roughly 885,000 phone numbers from several countries in an attempt to steal cryptocurrency holdings by redirecting victims to fake wallet-provider websites. Crypto Briefing similarly reports that a single misconfigured server exposed a directory containing approximately 885,000 phone numbers, automated tools for validating crypto exchange accounts, and counterfeit versions of hardware wallet software. Crypto Briefing states the report was published on August 17, 2026.
Both outlets agree the largest single batch of numbers was a German dataset of 316,002 mobile numbers. Cointelegraph reports additional directories covered Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and further Ledger-related lists — a geographic breakdown not present in Crypto Briefing’s account.
Both outlets report that attackers ran the German dataset against exchange account-validation systems, producing a hit rate both describe as approximately 13.6%. Cointelegraph specifies that this hit rate reflects 43,066 accounts matched to real users — a raw figure that does not appear in Crypto Briefing’s account, which states only the percentage.
Cointelegraph and Crypto Briefing align on the central facts of the disclosure:
The two fully-held sources part ways on several specific claims, and each is attributable to only one of them.
Cointelegraph alone reports that 5,576 accounts matched to users on crypto exchange Binance were queued for attack, and that recovered logs showed fake emails impersonating Crypto.com. Cointelegraph also states that Rapid7’s report identified a checker tool specifically designed to bulk-validate phone numbers against Kraken accounts. None of these three details — the Binance figure, the Crypto.com email impersonation, and the Kraken checker — appear in Crypto Briefing’s account of the same report.
Crypto Briefing, in turn, is the only fully-held source to report on the operation’s actual activity volume: recovered logs from the server showed just 20 lead lookups and six phishing emails sent over an approximately two-week period. Crypto Briefing is also the only fully-held source to state that Rapid7 coordinated with Apple’s security team as part of its disclosure process; Cointelegraph’s account, as provided, makes no mention of Apple. Crypto Briefing also states the operation specifically targeted Crypto.com users on the account-validation front — a framing that differs from Cointelegraph’s description of a Kraken-focused checker tool, though the two are not necessarily mutually exclusive since a single operation could run separate checkers against multiple exchanges.
Crypto Briefing additionally offers its own extrapolation, not attributed to Rapid7, that if the 13.6% hit rate were applied across the full 885,000-number database, the operation could theoretically identify more than 120,000 active exchange users. This is Crypto Briefing’s analysis of the disclosed figures rather than a number Rapid7 itself reported, and readers should treat it as such.
Cointelegraph situates the disclosure within a broader run of security incidents. The outlet reports that Trezor disclosed, earlier in August, that its shipping partner ShipMonk suffered a data breach exposing personal information for roughly 14,000 customers. Cointelegraph also reports that in July, an Ethereum investor lost close to $1 million by approving a fraudulent token transaction sent through a phishing link. And Cointelegraph notes a November 2023 case in which a counterfeit Ledger Live application distributed via the Microsoft Store led to $588,000 stolen across 38 separate transactions.
Cointelegraph also cites data from blockchain security firm Hacken showing that phishing attacks and social-engineering scams accounted for $306 million of the $482 million total lost by the crypto industry in the first quarter of the year. This figure does not appear in Crypto Briefing’s account and should be treated as single-sourced to Cointelegraph’s citation of Hacken.
Neither Cointelegraph nor Crypto Briefing states whether the campaign successfully compromised any victims’ funds, or how much, if any, cryptocurrency was actually stolen. Whether Binance or Kraken have issued any response to being named in connection with the report is not addressed by either outlet. The full extent of the campaign’s reach beyond the German dataset — including the Hong Kong, Bulgaria, UK, US and Canadian fintech lists Cointelegraph mentions — has not been independently verified by Crypto Briefing. The total number of individuals actually contacted or defrauded is not established in either account.
Cointelegraph reports it has contacted Rapid7 analysts Anna Sirokova and Jan Recinsky for further comment on target filtering, hardware wallet spoofing, and self-custody vulnerabilities, and says it will update its article when they respond. Whether exchanges named in connection with the account-validation tooling issue their own statements, and whether further technical detail from Rapid7 clarifies the discrepancy between the Binance and Kraken references in Cointelegraph’s account and the Crypto.com-centric framing in Crypto Briefing’s, are open questions for now.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.