AI-Powered Crypto Phishing and Hacking Threats Reach New Scale

1 hour ago 2 sources negative

Key takeaways:

  • AI-assisted phishing escalates hardware wallet risks; verify downloads directly from official sources.
  • Large-scale vishing data validation signals shift toward targeted, cost-efficient wallet theft.
  • Regulatory ambiguity around autonomous AI agents may slow Web3 adoption and require security frameworks.

Cybersecurity firm Rapid7 has exposed a highly targeted phishing and vishing operation known as Operation ASTERIX, revealing that artificial intelligence is now central to crypto wallet theft. The campaign leveraged a database of roughly 885,000 phone numbers, crypto account-validation tools, phishing emails, vishing calls, and counterfeit Trezor, Ledger and Exodus apps designed to steal recovery phrases.

The most dangerous element was a validation layer: in one German dataset, operators identified 43,066 CryptoCom accounts from 316,002 phone numbers, a hit rate high enough to make large-scale support impersonation viable. After confirming phone numbers linked to exchange accounts, attackers enriched profiles with personal details, making fake support calls far more convincing.

Rapid7 found signs that the group used AI coding assistants such as GitHub Copilot and Claude Code to process target data, develop and debug malicious software, and build phishing infrastructure. When one model refused code obfuscation requests, the operator attempted a custom jailbreak prompt against another AI tool, Kimi. Rapid7 could not confirm whether the jailbreak succeeded.

The warning extends beyond a single campaign. At the Wyoming Blockchain Symposium 2026, industry leaders including Global Settlement Network CEO Ryan Kirkley said autonomous AI agents could supercharge Web3 hacking. Kirkley argued that attackers previously avoided individual wallets because manual effort made such attacks inefficient; with AI agents, automated programs can simultaneously target Wi-Fi networks, passwords and wallets at scale.

Panelists also stressed regulatory gaps: there is no clear framework for who is responsible when an autonomous AI agent breaks the law or causes financial losses. This uncertainty is seen as a major obstacle to mass commercialization of AI agents in Web3.

Security researchers and platform providers are likely to scrutinize how aggressively coding assistance should be restricted around wallet-related software. Users are urged to download wallet apps only from official sources and to remember that hardware wallet vendors and exchange support teams will never ask for recovery phrases.

Sources
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.