Rapid7 Labs uncovered a targeted crypto fraud pipeline that used fake Trezor, Ledger and Exodus apps, a coordinated vishing operation, and AI coding assistants to steal recovery phrases from validated exchange users.
Cybersecurity firm Rapid7 has exposed one of the most methodical cryptocurrency fraud operations documented this year, a multi-stage phishing and vishing pipeline that used counterfeit Trezor Suite, Ledger Live and Exodus applications to steal recovery phrases from crypto users after validating them against real exchange accounts.
In a report published on August 17 by Rapid7 Labs researchers Anna Širokova and Jan Recinsky, the firm said it uncovered the campaign, which it tracks as Operation ASTERIX, after finding a misconfigured web directory on the operator’s infrastructure.
The exposed server contained approximately 885,000 phone numbers, account-validation tools targeting Crypto.com, Binance and Kraken, fake wallet builds for macOS and Windows, phishing panels, dialer scripts, LaunchAgent persistence files and complete session logs from the LLMs the operator used to develop the malware.
Keystone flagged the disclosure to its user base on X, using the fake Trezor sample as a talking point in the broader hardware wallet trust debate.
How The Operation Selected Its Victims
The campaign did not rely on mass phishing. According to Rapid7, the operator used a Go-based checker to hit Crypto.com’s passkey-verification endpoint through 300 concurrent threads and rotating residential proxies from Bright Data, validating which numbers were tied to real Crypto.com accounts. Against a German dataset of 316,002 mobile numbers, the checker confirmed 43,066 accounts, a hit rate of roughly 13.6%.
A separate Kraken checker communicated with a command server at 136.0.213.184:1337. Ledger-related lists were split across 54 country files, and the operator kept enriched-lead databases with names, email addresses, phone numbers, geographic detail, account context and, in some cases, payment-card information. Only after enrichment did the outreach begin.
The recovered logs from one phishing panel showed just 20 lead lookups and six phishing emails over roughly two weeks, activity consistent with operators handling calls individually rather than running an automated blast. This was a targeted operation aimed at users the attacker had already confirmed held crypto.
Fake Wallet Apps Did The Real Damage
The core payload was the counterfeit software. Rapid7 recovered fake Trezor Suite, Ledger Live and Exodus applications for macOS and Windows. The Trezor build was the most developed, packaged in Electron and produced in three variants that shared the same 5.87 MB app.asar payload with SHA-256 hash ba9d459169a303067a4fe36c8b8582a5ea023b9c270dafe89613bab840501b19.
The Trezor sample did not show a phishing screen immediately. It started as a hidden Electron process that opened a single-pixel, fully transparent, frameless BrowserWindow that stayed off the taskbar, and then quietly waited for the user to open the real Trezor Suite. Every five seconds it scanned the process list for the legitimate app, and when it found it, it terminated it with kill -9, brought its own hidden window forward, and reactivated the app by name through AppleScript.
From the victim’s side, opening the real wallet just produced another Trezor Suite window. The fake window then asked for the 12-, 18-, 20- or 24-word recovery phrase and an optional passphrase, and pushed a fake validation error after the first submission so the user would enter the phrase again more carefully. The stolen phrase, passphrase and victim IP address, retrieved from api.ipify.org, were sent to a Telegram bot with the fixed prefix “TREZOR SECRET PHRASE” before the user was redirected to the real Trezor Suite website.
Persistence on macOS relied on two LaunchAgents, com.trezormovement.agent written at runtime and io.trezor.agent bundled with the app, both of which relaunched the malware at login. The Windows build had inert persistence and process-replacement code that never ran because of a configuration bug, leaving it functional only as a static seed-phrase collector.
The Ledger Live build added a clipboard hijacker on Windows that silently replaced any copied cryptocurrency address with an attacker-controlled one, and hid itself entirely from the macOS Dock through the LSUIElement flag. The Exodus installer looked clean on inspection because the malicious code was not in it; a trojanised jQuery file fetched the real payload from a remote server after installation.
Fake Claude Installer Dropped Fake Ledger
The operators also hosted a trojanised Claude Code installer on macos-claude[.]com, a near pixel-perfect copy of Anthropic’s official Claude Code quickstart page, complete with scraped AnthropicSans and AnthropicSerif fonts and links back to the real Anthropic site.
The macOS installation command on the page had been replaced with a script that installed a fake Ledger Live application into a hidden ~/Library/Application Support/.SystemData/.framework/.apps/ directory, wired up a LaunchAgent for persistence, and then executed the legitimate Claude installer from claude.ai/install.sh so the user actually received Claude Code as expected.
Infrastructure And Disclosure
The operation ran on a compact stack centred on a single host, using port 8000 to serve counterfeit wallet archives, port 8080 for installers and LaunchAgent files, port 5000 for password-protected Flask panels, and port 9000 for installation telemetry. Outbound phishing emails were sent through Aliyun DirectMail, and three Telegram bots forwarded stolen results to a command chat. The domains macos-claude[.]com, 36mcrypto[.]com, ledgerhelp[.]com and ledger[.]com[.]lv supported various stages of the campaign.
The unauthenticated directory listing on port 8080 is what handed Rapid7 the whole environment, including the operator’s source code, target datasets, databases and build artefacts. Rapid7 said it disclosed the identified infrastructure to Apple’s security team and other relevant service providers and authorities while parts of the operation were still active.
The exposure lands in a month already dominated by hardware wallet security failures. The ongoing Coldcard exploit, which stems from a March 2021 firmware flaw that weakened seed generation entropy, has drained roughly $116 million in Bitcoin from more than 5,200 addresses since July 30, and continues to trigger defensive migrations of dormant supply across the network. The Crypto Times has also tracked the ETF-versus-self-custody debate the incident reopened and the broader security crisis it exposed.
Binance founder Changpeng Zhao earlier warned users not to place blind trust in hardware wallets, and Rapid7’s report reinforces the point from the other direction, showing that the software surrounding those wallets is being weaponised with production-grade tooling.
Analyst Take
Nothing in Rapid7’s technical breakdown is novel by itself. Fake wallet apps, Telegram exfiltration, LaunchAgent persistence, clipboard hijacking, coordinated email-plus-call scams and account enumeration against exchange APIs have all been documented before. What Operation ASTERIX changes is the calibre of the operator.
The account validation stage alone is a shift. Instead of dialling random numbers, the operator was starting outreach with a name, an exchange, an email address and, in some cases, a payment-card context, then reinforcing the pretext with a fake case number that appeared in both the email and the call. That is not a low-effort script kiddie funnel. That is a mid-tier fraud shop running an enterprise sales pipeline in reverse.
The AI angle is where the report gets uncomfortable. The operator did not use LLMs for a one-off code snippet; they used them as day-to-day engineering assistants, and when one model resisted, they switched providers and tried to defeat the next model’s safety layer with a thousand-word jailbreak that specifically referenced Claude’s system-prompt architecture. That kind of behaviour is going to normalise across the fraud ecosystem faster than model vendors can patch it. The Coldcard exploit showed how a single firmware bug can drain hundreds of wallets. Operation ASTERIX shows how a single operator with a laptop, a proxy pool and an LLM subscription can build the pipeline to convince the survivors to hand over what is left.
For end users, the defensive posture is simple even if the ecosystem answer is not. Downloads only from official vendor pages, no seed phrases into any software regardless of how convincing the window looks, and hardware wallets used with air-gapped signing where possible. Everything Rapid7 documented in this operation ultimately relies on the victim typing their recovery phrase somewhere it should never be typed.
Also Read: India Arrests 13 Over Fake Apple Support Crypto Scam
