Cybersecurity firm Rapid7 says an automated phishing operation targeted crypto users through a massive trove of exposed phone numbers.
Cybersecurity firm Rapid7 has disclosed a phishing operation targeting cryptocurrency users that exposed 885,000 phone numbers. The firm said the campaign relied on artificial intelligence tools to automate and scale its outreach. Rapid7’s findings point to a coordinated effort aimed squarely at crypto holders rather than a broad, untargeted scam.
Phishing has long been a persistent threat in the digital asset industry. Attackers frequently pose as exchanges, wallet providers, or support staff to trick victims into revealing credentials or private keys. The addition of AI tools can make these campaigns faster to run and harder to detect, since automated systems can generate messages and manage large contact lists with minimal human oversight.
The scale of the exposure, nearly 900,000 phone numbers, underscores how phishing operations can gather large pools of contact data before deploying attacks. Rapid7 did not, according to the reporting, specify how the numbers were originally obtained. It remains unclear whether the data came from a single breach, a combination of leaked databases, or other sourcing methods.
Crypto users remain frequent targets because successful phishing attempts can lead directly to irreversible losses. Unlike traditional banking, most cryptocurrency transactions cannot be reversed once funds are moved. This makes the sector especially attractive to attackers using automated tools designed to reach as many potential victims as possible.
Rapid7 is known for tracking cybersecurity threats across multiple industries, including finance and digital assets. Its disclosure adds to a growing body of research documenting how AI is being integrated into cybercrime operations. Security researchers have repeatedly warned that generative AI tools lower the barrier to running convincing, large-scale phishing campaigns.
The firm’s findings are likely to prompt renewed scrutiny of how phone number databases tied to crypto services are protected. Exchanges, wallet providers, and related platforms often collect phone numbers for two-factor authentication and account verification. If such data is exposed or harvested, it can become a direct pipeline for follow-on scams like SIM-swapping or targeted phishing texts.
The disclosure is unlikely to move cryptocurrency prices directly, but it highlights ongoing security risks within the industry’s infrastructure. Exchanges and wallet providers may face pressure to review how they store and protect user phone numbers and other contact data.
For individual investors, the report is a reminder to remain cautious with unsolicited messages referencing crypto accounts. Heightened awareness of AI-assisted phishing could also accelerate demand for stronger authentication methods across the sector, including hardware-based security keys and improved verification protocols.
Rapid7’s findings add to mounting evidence that AI tools are reshaping the scale and sophistication of crypto-targeted phishing. As the investigation continues, further details on the operation’s origins and full scope may still emerge.
Rapid7 identified a crypto-focused phishing operation that exposed 885,000 phone numbers and used AI tools to automate its outreach.
The specific method used to gather or expose the phone numbers has not been detailed in current reporting.
Cryptocurrency transactions are generally irreversible, making successful phishing attacks especially costly for victims and attractive to attackers.
The report focuses on a security issue rather than market fundamentals, so it is not expected to directly influence prices.
Original source: AltcoinGordon
Syndicated coverage. Originally reported by altcoingordon.com.