Invest1 publisher3 min readPublished
Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.
Rapid7's Operation ASTERIX report shows the cost of building convincing wallet malware collapsing while targeting stayed manual. The durable asset is the validated list, not the code.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Rapid7 Labs uncovered Operation ASTERIX, a crypto fraud pipeline that used AI coding assistants to create fake Ledger, Trezor and Exodus apps; the pair's report was dated August 17.
- An exposed web directory on campaign infrastructure was discovered by Rapid7 researchers Anna Širokova and Jan Recinsky.
- The AI coding tool used was GitHub Copilot, and Rapid7 found AI assistants were used across the entire development process, not just for isolated snippets.
- Rapid7's summary states the operators validated 43,066 of about 885,000 leaked phone numbers as real crypto exchange users.
- The open directory contained around 885,000 phone numbers.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Rapid7 Labs published on August 17 the anatomy of a live crypto phishing pipeline it calls Operation ASTERIX, found by researchers Anna Širokova and Jan Recinsky after the operators left a web directory exposed on their own infrastructure [1][2]. Two details matter for anyone holding customer records: the crew used GitHub Copilot across the entire build of counterfeit Ledger, Trezor and Exodus apps, and it had already confirmed that 43,066 phone numbers on a leaked list belonged to real crypto exchange users [3][4].
The open directory held roughly 885,000 phone numbers, of which the largest single file was 316,002 German mobile numbers [5][6]. Rapid7 says the operators ran those German numbers through an account checker and confirmed 43,066 as exchange users, a hit rate of about 13.6 percent [7]. Read that denominator carefully. The headline summary frames the 43,066 against the full 885,000 [4], but the report's own detail attributes the checks to the German file, which is about 36 percent of the total set [1]. Smaller directories covered Hong Kong, Bulgaria, the UK, the US, Canadian fintech customers and Ledger-related lists [8]. A further 5,576 numbers tied to Binance accounts were queued for attack, roughly one in eight of the validated pool [9][2], and the server also held a Kraken checker and fake emails posing as Crypto.com [10].
The payload is unglamorous and effective. The apps imitate Trezor Suite and Ledger Live, with Exodus also spoofed, and ask the user to type a 12 to 24 word recovery phrase [11]. That phrase is the master key to the wallet, and it was exfiltrated over Telegram [12][13]. Recovered prompts, shell history and project files show AI assistants used to package the Electron apps, obfuscate code, fix builds and prepare the malware for distribution, not merely to produce snippets [14][15]. When one model started refusing parts of the work, Rapid7 says the operator switched providers and tried a custom jailbreak prompt on the next one [16].
Then the activity logs deflate the picture. They record only 20 lead lookups across about two weeks and six phishing emails sent, which Rapid7 reads as slow hand-picked targeting rather than mass contact [17][18]. At 20 lookups per fortnight, working through 43,066 validated targets would take on the order of 80 years [3]. So the assistant compressed engineering, not conversion. The bottleneck is the human on the Asterisk telephony rig recovered from the server, placing voice-phishing calls timed to land alongside fake support emails the victim had already received [19][20].
That reorders the risk. The scarce input is not code, it is a list of confirmed self-custody customers with a phone number attached, and that list comes from your vendors. Earlier in August, Trezor warned 13,689 customers after a breach at shipping partner ShipMonk exposed names, emails, phone numbers and addresses [21]. Ledger and Trezor owners have also received physical letters carrying QR codes to phishing sites, according to Cryptopolitan reporting in February [22]. Hacken puts phishing and social engineering at $306 million of the industry's $482 million in first-quarter losses, about 64 percent [23][4].
Watch three things. Whether Copilot-class vendors can detect this build pattern, given the operator's response to refusal was to switch providers [16]. Whether logistics and support partners get treated as wallet-security surface after ShipMonk [21]. And whether the manual bottleneck holds: the campaign was still running when Rapid7 found it, and the firm said it was able to notify providers and authorities including Apple's security team mid-campaign [24][25].