Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Rapid7, Monday, August 17th, 2026
Rapid7 found an exposed directory revealing a full cryptocurrency fraud toolkit built with AI coding assistants.
Rapid7 researchers identified an exposed web directory on infrastructure supporting a cryptocurrency fraud operation they named Operation ASTERIX.
The server held raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms and Telegram exfiltration code. Together the artifacts document the full pipeline from lead acquisition through to theft.
Among them was evidence that the operator relied on AI coding assistants throughout development, including recovered prompts, shell history and project files. Rapid7 uses the find to show how AI tooling is changing the economics of fraud operations.