Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation

Rapid7 found a crypto scammer used Claude Code on more than 100,000 phone numbers in a phishing and vishing operation targeting cryptocurrency holders.

Written By
LT
Liz Ticong
Aug 19, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A cryptocurrency scammer used Anthropic’s Claude Code on more than 100,000 phone numbers as part of a phishing and vishing operation targeting cryptocurrency users.

Rapid7 uncovered the activity while investigating exposed infrastructure tied to a fraud campaign tracked as Operation ASTERIX. Researchers found roughly 885,000 phone numbers on the server, with records showing how AI had become part of the operator’s workflow.

Recovered files gave investigators an unusually detailed look inside the campaign. Evidence showed how a large pool of phone data was gradually narrowed before selected people were approached.

Raw phone lists became verified crypto leads

Phone records on the exposed server spanned several countries and data sources. Rapid7 found tools that checked whether individual numbers were associated with cryptocurrency platforms.

One German dataset contained 316,002 mobile numbers. An automated Crypto.com checker confirmed 43,066 accounts, or about 13.6% of the list.

Confirmed matches could then be enriched with names, email addresses, locations, and account information. Personal details can make social engineering attacks more convincing because a scammer may already know which service someone uses before making contact.

A recovered Binance lead panel showed 5,576 validated crypto targets queued for attack. 

Phishing calls and fake wallets moved targets toward theft

Email and phone contact worked in sequence. The phishing messages included case numbers or verification codes that callers could reference during follow-up calls. 

Call infrastructure using Asterisk and 3CX supported automated outbound dialing. Operators could approach someone already knowing a name, location, or likely exchange association, a technique also seen in hybrid vishing campaigns.

Recovered malware added another route to cryptocurrency theft. Counterfeit versions of Trezor Suite, Ledger Live, and Exodus were found for Windows and macOS.

Fake Trezor software could capture wallet recovery phrases, and a malicious Ledger Live build could replace a copied cryptocurrency address with one controlled by the attacker. Similar cryptocurrency theft schemes have used malicious browser extensions and clipboard manipulation to redirect funds.

Advertisement

Claude did not comply with every request, though. When the operator asked for help obfuscating the malicious Ledger Live build and preparing versions for distribution, the AI assistant refused.

The scammer then moved to Kimi K2.7 Code and submitted a jailbreak prompt intended to bypass its safeguards. Rapid7 could not determine whether the attempt succeeded.

Crypto users need to verify support contacts independently

If you use a cryptocurrency exchange or hardware wallet, someone knowing your name, email address or platform does not prove they work for that company. Scammers may already have verified your account association before they call.

  • End unexpected support calls. If someone contacts you about a wallet problem or account verification, hang up and contact the provider through its official app or website.
  • Never share recovery credentials. Seed phrases and recovery phrases should not be given to anyone claiming to be support.
  • Avoid software sent through unsolicited messages. Do not install wallet applications through links, downloads, or commands provided during a call or email.
  • Use stronger account protection. Enable phishing-resistant MFA on exchange accounts where available.
  • Act quickly after suspected exposure. If you entered a recovery phrase into suspicious software or a website, treat it as compromised and follow the wallet provider’s official recovery guidance.

Exchange and wallet providers can reduce exposure by limiting account-enumeration attempts, rate-limiting suspicious validation traffic, and monitoring repeated requests from rotating proxies. 

More security news: A hacker claims to be selling 3.6 million Azure-linked employee records tied to McDonald’s, Vodafone, TCS, and other companies.

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.