
Key takeaways
- Attackers target 885,000 phone numbers across multiple regions in a campaign built to steal wallet seed phrases
- The campaign combines unsolicited calls, deceptive links, and requests for authentication codes from potential victims
- Wallet owners protect funds by withholding seed phrases, no matter how convincing a caller sounds
A phishing campaign targeted 885,000 phone numbers in an attempt to steal cryptocurrency, Atlas21 reported. The attackers sought wallet seed phrases, the recovery secrets that let whoever holds them reach a victim's funds.
Operation Asterix Turns the Phone Into an Attack Surface
Rapid7 described the campaign as Operation Asterix and linked it to both voice phishing and online phishing. The approach combined phone contact with deceptive links and social engineering, rather than relying on a single technical exploit.
The target was not merely an account password. Attackers sought seed phrases that can restore control of a wallet, which makes a successful disclosure far more damaging than surrendering a credential a service provider can reset. A persuasive voice, familiar branding, or an urgent message cannot change that custody boundary.
The reported scale (885,000 phone numbers) gave the campaign a broad pool of potential targets. Its effectiveness still depended on individuals answering unsolicited calls, visiting untrusted links, sharing authentication codes, or handing over wallet recovery words.
The Custody Rules Do Not Bend for Better AI
Reporting on the campaign said attackers were using tools assisted by AI to make phishing and social engineering more sophisticated. Those tools can sharpen the appearance or delivery of a scam, but they do not change the basic route to the funds: the victim still has to be talked into disclosing a secret or approving access.
The practical defense stays direct. Wallet owners should never share a seed phrase with another person, no matter how reliable that person sounds. They should also avoid answering random numbers, opening unexpected links, or sharing authentication codes requested through an unsolicited contact.
Keeping track of current scam methods can help users spot pressure tactics before money moves. The decisive check is simpler than identifying every tool an attacker used: a legitimate helper never needs a wallet's recovery phrase, and an incoming call earns no trust merely by reciting accurate personal details.
Why It Matters
Operation Asterix targeted 885,000 phone numbers because self-custody concentrates authority in a secret the owner controls. That sovereignty has a hard edge: no bank can reverse the disclosure of a seed phrase, and no convincing caller deserves the words that recreate a wallet. Phishing that leans on AI tools may make a lie more polished, but it cannot bypass Bitcoin's custody rules without obtaining a key or an approval. The strongest defense is procedural rather than theatrical: protect the seed phrase, distrust unsolicited contact, verify requests through a separate channel, and treat authentication codes as access rather than harmless text.



















