Cybersecurity firm Rapid7 has exposed a highly targeted phishing and vishing operation known as Operation ASTERIX, revealing that artificial intelligence is now central to crypto wallet theft. The campaign leveraged a database of roughly 885,000 phone numbers, crypto account-validation tools, phishing emails, vishing calls, and counterfeit Trezor, Ledger and Exodus apps designed to steal recovery phrases.
The most dangerous element was a validation layer: in one German dataset, operators identified 43,066 CryptoCom accounts from 316,002 phone numbers, a hit rate high enough to make large-scale support impersonation viable. After confirming phone numbers linked to exchange accounts, attackers enriched profiles with personal details, making fake support calls far more convincing.
Rapid7 found signs that the group used AI coding assistants such as GitHub Copilot and Claude Code to process target data, develop and debug malicious software, and build phishing infrastructure. When one model refused code obfuscation requests, the operator attempted a custom jailbreak prompt against another AI tool, Kimi. Rapid7 could not confirm whether the jailbreak succeeded.
The warning extends beyond a single campaign. At the Wyoming Blockchain Symposium 2026, industry leaders including Global Settlement Network CEO Ryan Kirkley said autonomous AI agents could supercharge Web3 hacking. Kirkley argued that attackers previously avoided individual wallets because manual effort made such attacks inefficient; with AI agents, automated programs can simultaneously target Wi-Fi networks, passwords and wallets at scale.
Panelists also stressed regulatory gaps: there is no clear framework for who is responsible when an autonomous AI agent breaks the law or causes financial losses. This uncertainty is seen as a major obstacle to mass commercialization of AI agents in Web3.
Security researchers and platform providers are likely to scrutinize how aggressively coding assistance should be restricted around wallet-related software. Users are urged to download wallet apps only from official sources and to remember that hardware wallet vendors and exchange support teams will never ask for recovery phrases.