Security researchers at Rapid7 have pulled back the curtain on a sophisticated cryptocurrency scam dubbed Operation ASTERIX, revealing a highly organized pipeline designed to drain digital wallets. The discovery happened by chance when investigators found an exposed web directory containing the entire backend of the fraudulent operation. Inside, they discovered everything from massive databases of phone numbers and phishing panels to fake versions of popular wallet applications like Ledger and Trezor. The name ASTERIX comes from the open source telephony platform the attackers used to coordinate automated voice calls with deceptive emails, creating a seamless trap for unsuspecting investors.

What makes this case particularly alarming is the extent to which the operators leaned on artificial intelligence to build their toolkit. Rather than just using AI to write simple emails, the criminals used AI coding assistants to package complex applications, hide their malicious code from security software, and troubleshoot technical bugs in real time. In a telling detail about the cat and mouse game between hackers and tech companies, researchers found evidence that when one AI model refused to help with certain illegal tasks, the operator simply switched providers and employed custom jailbreak prompts to bypass safety filters.

The actual attack process functioned like a precision funnel. The scammers started with nearly nine hundred thousand phone numbers globally and used specialized tools to ping cryptocurrency exchanges, confirming exactly which individuals held active accounts. Once they had a verified list of targets, they launched coordinated strikes involving fake support tickets and urgent phone calls meant to build trust. These interactions eventually lured victims into downloading counterfeit wallet apps that stole their private recovery phrases and beamed them directly to the attackers via Telegram.

Because much of this infrastructure was still active when it was uncovered, Rapid7 was able to alert authorities and companies like Apple in time to disrupt the operation. By mapping out this kill chain, experts hope other security teams can better detect these patterns before users lose their funds. The breach serves as a stark reminder that while AI provides immense benefits for legitimate developers, it is also rapidly lowering the barrier for cybercriminals to deploy industrial scale fraud operations.