Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Rapid7 Exposes Fake Trezor App Used to Steal Crypto Seed Phrases

Rapid7 found attackers screening 316,002 German phone numbers and identifying 43,066 verified Crypto.com accounts.

Written By Dishita Malvania
Edited by Divya Mistry
Published 45 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Rapid7 Exposes Fake Trezor App Used to Steal Crypto Seed Phrases

Rapid7 Labs uncovered a targeted crypto fraud pipeline that used fake Trezor, Ledger and Exodus apps, a coordinated vishing operation, and AI coding assistants to steal recovery phrases from validated exchange users.

Cybersecurity firm Rapid7 has exposed one of the most methodical cryptocurrency fraud operations documented this year, a multi-stage phishing and vishing pipeline that used counterfeit Trezor Suite, Ledger Live and Exodus applications to steal recovery phrases from crypto users after validating them against real exchange accounts.

AI Summary
Show
Operation ASTERIX shows fraudsters now validate exchange accounts before attacks, raising the bar for crypto phishing.
Fake hardware‑wallet apps coupled with AI‑generated malware illustrate growing weaponisation of wallet software ecosystems.
Disclosure highlights industry‑wide hardware wallet trust crisis, prompting exchanges and regulators to reassess user security protocols.

In a report published on August 17 by Rapid7 Labs researchers Anna Širokova and Jan Recinsky, the firm said it uncovered the campaign, which it tracks as Operation ASTERIX, after finding a misconfigured web directory on the operator’s infrastructure. 

The exposed server contained approximately 885,000 phone numbers, account-validation tools targeting Crypto.com, Binance and Kraken, fake wallet builds for macOS and Windows, phishing panels, dialer scripts, LaunchAgent persistence files and complete session logs from the LLMs the operator used to develop the malware.

Keystone flagged the disclosure to its user base on X, using the fake Trezor sample as a talking point in the broader hardware wallet trust debate.

How The Operation Selected Its Victims

The campaign did not rely on mass phishing. According to Rapid7, the operator used a Go-based checker to hit Crypto.com’s passkey-verification endpoint through 300 concurrent threads and rotating residential proxies from Bright Data, validating which numbers were tied to real Crypto.com accounts. Against a German dataset of 316,002 mobile numbers, the checker confirmed 43,066 accounts, a hit rate of roughly 13.6%.

A separate Kraken checker communicated with a command server at 136.0.213.184:1337. Ledger-related lists were split across 54 country files, and the operator kept enriched-lead databases with names, email addresses, phone numbers, geographic detail, account context and, in some cases, payment-card information. Only after enrichment did the outreach begin.

The recovered logs from one phishing panel showed just 20 lead lookups and six phishing emails over roughly two weeks, activity consistent with operators handling calls individually rather than running an automated blast. This was a targeted operation aimed at users the attacker had already confirmed held crypto.

Fake Wallet Apps Did The Real Damage

The core payload was the counterfeit software. Rapid7 recovered fake Trezor Suite, Ledger Live and Exodus applications for macOS and Windows. The Trezor build was the most developed, packaged in Electron and produced in three variants that shared the same 5.87 MB app.asar payload with SHA-256 hash ba9d459169a303067a4fe36c8b8582a5ea023b9c270dafe89613bab840501b19.

The Trezor sample did not show a phishing screen immediately. It started as a hidden Electron process that opened a single-pixel, fully transparent, frameless BrowserWindow that stayed off the taskbar, and then quietly waited for the user to open the real Trezor Suite. Every five seconds it scanned the process list for the legitimate app, and when it found it, it terminated it with kill -9, brought its own hidden window forward, and reactivated the app by name through AppleScript.

From the victim’s side, opening the real wallet just produced another Trezor Suite window. The fake window then asked for the 12-, 18-, 20- or 24-word recovery phrase and an optional passphrase, and pushed a fake validation error after the first submission so the user would enter the phrase again more carefully. The stolen phrase, passphrase and victim IP address, retrieved from api.ipify.org, were sent to a Telegram bot with the fixed prefix “TREZOR SECRET PHRASE” before the user was redirected to the real Trezor Suite website.

Persistence on macOS relied on two LaunchAgents, com.trezormovement.agent written at runtime and io.trezor.agent bundled with the app, both of which relaunched the malware at login. The Windows build had inert persistence and process-replacement code that never ran because of a configuration bug, leaving it functional only as a static seed-phrase collector.

The Ledger Live build added a clipboard hijacker on Windows that silently replaced any copied cryptocurrency address with an attacker-controlled one, and hid itself entirely from the macOS Dock through the LSUIElement flag. The Exodus installer looked clean on inspection because the malicious code was not in it; a trojanised jQuery file fetched the real payload from a remote server after installation.

Fake Claude Installer Dropped Fake Ledger

The operators also hosted a trojanised Claude Code installer on macos-claude[.]com, a near pixel-perfect copy of Anthropic’s official Claude Code quickstart page, complete with scraped AnthropicSans and AnthropicSerif fonts and links back to the real Anthropic site. 

The macOS installation command on the page had been replaced with a script that installed a fake Ledger Live application into a hidden ~/Library/Application Support/.SystemData/.framework/.apps/ directory, wired up a LaunchAgent for persistence, and then executed the legitimate Claude installer from claude.ai/install.sh so the user actually received Claude Code as expected.

Infrastructure And Disclosure

The operation ran on a compact stack centred on a single host, using port 8000 to serve counterfeit wallet archives, port 8080 for installers and LaunchAgent files, port 5000 for password-protected Flask panels, and port 9000 for installation telemetry. Outbound phishing emails were sent through Aliyun DirectMail, and three Telegram bots forwarded stolen results to a command chat. The domains macos-claude[.]com, 36mcrypto[.]com, ledgerhelp[.]com and ledger[.]com[.]lv supported various stages of the campaign.

The unauthenticated directory listing on port 8080 is what handed Rapid7 the whole environment, including the operator’s source code, target datasets, databases and build artefacts. Rapid7 said it disclosed the identified infrastructure to Apple’s security team and other relevant service providers and authorities while parts of the operation were still active.

The exposure lands in a month already dominated by hardware wallet security failures. The ongoing Coldcard exploit, which stems from a March 2021 firmware flaw that weakened seed generation entropy, has drained roughly $116 million in Bitcoin from more than 5,200 addresses since July 30, and continues to trigger defensive migrations of dormant supply across the network. The Crypto Times has also tracked the ETF-versus-self-custody debate the incident reopened and the broader security crisis it exposed.

Binance founder Changpeng Zhao earlier warned users not to place blind trust in hardware wallets, and Rapid7’s report reinforces the point from the other direction, showing that the software surrounding those wallets is being weaponised with production-grade tooling.

Analyst Take

Nothing in Rapid7’s technical breakdown is novel by itself. Fake wallet apps, Telegram exfiltration, LaunchAgent persistence, clipboard hijacking, coordinated email-plus-call scams and account enumeration against exchange APIs have all been documented before. What Operation ASTERIX changes is the calibre of the operator.

The account validation stage alone is a shift. Instead of dialling random numbers, the operator was starting outreach with a name, an exchange, an email address and, in some cases, a payment-card context, then reinforcing the pretext with a fake case number that appeared in both the email and the call. That is not a low-effort script kiddie funnel. That is a mid-tier fraud shop running an enterprise sales pipeline in reverse.

The AI angle is where the report gets uncomfortable. The operator did not use LLMs for a one-off code snippet; they used them as day-to-day engineering assistants, and when one model resisted, they switched providers and tried to defeat the next model’s safety layer with a thousand-word jailbreak that specifically referenced Claude’s system-prompt architecture. That kind of behaviour is going to normalise across the fraud ecosystem faster than model vendors can patch it. The Coldcard exploit showed how a single firmware bug can drain hundreds of wallets. Operation ASTERIX shows how a single operator with a laptop, a proxy pool and an LLM subscription can build the pipeline to convince the survivors to hand over what is left.

For end users, the defensive posture is simple even if the ecosystem answer is not. Downloads only from official vendor pages, no seed phrases into any software regardless of how convincing the window looks, and hardware wallets used with air-gapped signing where possible. Everything Rapid7 documented in this operation ultimately relies on the victim typing their recovery phrase somewhere it should never be typed.

Also Read: India Arrests 13 Over Fake Apple Support Crypto Scam

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

$CLOCKIN Launch Sparks Sniping Concerns on StonkBroker
$CLOCKIN Launch Sparks Sniping Concerns on StonkBroker
User Loses 1,010 ETH in Phishing Attack via Hijacked Tornado Cash Domain
User Loses 1,010 ETH in Phishing Attack via Hijacked Tornado Cash Domain
Altcoin Market Cap Crosses $1 Trillion as ETH, SOL, XRP, and ZEC Rally 7-10% in Hours
Altcoin Market Cap Crosses $1 Trillion as ETH, SOL, XRP, and ZEC Rally 7-10% in Hours
X in Talks to Use Stablecoins Like USDC for Creator Royalties Report
Elon Musk’s X in Talks to Use Stablecoins Like USDC for Creator Royalties: Report
Bitcoin Treasury Stocks Rally as BTC Price Surges Past $72,000 MSTR, ASST, MARA jumps over 12%
Bitcoin Treasury Stocks Rally as BTC Price Surges Past $72,000: MSTR, ASST, MARA jumps over 12%

Find Us on Socials

You may also like

OKX Restricts Claude Access for Hong Kong Employees

OKX Restricts Claude Access for Hong Kong Employees

Spot Bitcoin ETFs Log $517M in Net Inflows, Largest in Over 3 Months

Spot Bitcoin ETFs Log $517M in Net Inflows, Largest in Over 3 Months

Crypto Markets Hit $3B Liquidation Wave as Bitcoin, ETH and XRP Prices Rally

Crypto Markets Hit $3B Liquidation Wave as Bitcoin, ETH and XRP Prices Rally

Crypto Market Advances as Treasury Expands Long-End Buybacks and Regulators Signal Clarity

Crypto Market Advances as Treasury Expands Long-End Buybacks and Regulators Signal Clarity

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information