Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation

Rapid7 found a crypto scammer used Claude Code on more than 100,000 phone numbers in a phishing and vishing operation targeting cryptocurrency holders.

Written By
Liz Ticong
Liz Ticong
Aug 19, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A cryptocurrency scammer used Anthropic’s Claude Code on more than 100,000 phone numbers as part of a phishing and vishing operation targeting cryptocurrency users.

Rapid7 uncovered the activity while investigating exposed infrastructure tied to a fraud campaign tracked as Operation ASTERIX. Researchers found roughly 885,000 phone numbers on the server, with records showing how AI had become part of the operator’s workflow.

Recovered files gave investigators an unusually detailed look inside the campaign. Evidence showed how a large pool of phone data was gradually narrowed before selected people were approached.

Raw phone lists became verified crypto leads

Phone records on the exposed server spanned several countries and data sources. Rapid7 found tools that checked whether individual numbers were associated with cryptocurrency platforms.

One German dataset contained 316,002 mobile numbers. An automated Crypto.com checker confirmed 43,066 accounts, or about 13.6% of the list.

Confirmed matches could then be enriched with names, email addresses, locations, and account information. Personal details can make social engineering attacks more convincing because a scammer may already know which service someone uses before making contact.

A recovered Binance lead panel showed 5,576 validated crypto targets queued for attack. 

Phishing calls and fake wallets moved targets toward theft

Email and phone contact worked in sequence. The phishing messages included case numbers or verification codes that callers could reference during follow-up calls. 

Call infrastructure using Asterisk and 3CX supported automated outbound dialing. Operators could approach someone already knowing a name, location, or likely exchange association, a technique also seen in hybrid vishing campaigns.

Recovered malware added another route to cryptocurrency theft. Counterfeit versions of Trezor Suite, Ledger Live, and Exodus were found for Windows and macOS.

Fake Trezor software could capture wallet recovery phrases, and a malicious Ledger Live build could replace a copied cryptocurrency address with one controlled by the attacker. Similar cryptocurrency theft schemes have used malicious browser extensions and clipboard manipulation to redirect funds.

Advertisement

Claude did not comply with every request, though. When the operator asked for help obfuscating the malicious Ledger Live build and preparing versions for distribution, the AI assistant refused.

The scammer then moved to Kimi K2.7 Code and submitted a jailbreak prompt intended to bypass its safeguards. Rapid7 could not determine whether the attempt succeeded.

Crypto users need to verify support contacts independently

If you use a cryptocurrency exchange or hardware wallet, someone knowing your name, email address or platform does not prove they work for that company. Scammers may already have verified your account association before they call.

  • End unexpected support calls. If someone contacts you about a wallet problem or account verification, hang up and contact the provider through its official app or website.
  • Never share recovery credentials. Seed phrases and recovery phrases should not be given to anyone claiming to be support.
  • Avoid software sent through unsolicited messages. Do not install wallet applications through links, downloads, or commands provided during a call or email.
  • Use stronger account protection. Enable phishing-resistant MFA on exchange accounts where available.
  • Act quickly after suspected exposure. If you entered a recovery phrase into suspicious software or a website, treat it as compromised and follow the wallet provider’s official recovery guidance.

Exchange and wallet providers can reduce exposure by limiting account-enumeration attempts, rate-limiting suspicious validation traffic, and monitoring repeated requests from rotating proxies. 

More security news: A hacker claims to be selling 3.6 million Azure-linked employee records tied to McDonald’s, Vodafone, TCS, and other companies.

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.