A Crypto Scammer Used Claude Code to Process 885,000 Phone Numbers for Fraud Targeting
Cybersecurity

A Crypto Scammer Used Claude Code to Process 885,000 Phone Numbers for Fraud Targeting

Rapid7 found an exposed server showing an operator used Claude Code to clean and prioritize hundreds of thousands of phone numbers, then switched to a jailbroken model once Claude refused to help build wallet-draining malware.

PublishedAugust 22, 2026
Read time5 min read
Share

An exposed server reveals the whole pipeline

Rapid7 researchers uncovered Operation ASTERIX after locating a web directory left exposed by the operators themselves, a routine operational security failure that handed investigators a full view of a working cryptocurrency fraud pipeline. The server held raw contact lists, lead databases, email panels, calling tools, counterfeit wallet applications, and documentation of the attack infrastructure, published in findings dated August 18, 2026, giving defenders an unusually complete look at how a modern fraud operation is actually assembled from working parts.

What made the discovery notable beyond the fraud mechanics themselves was evidence that the operator used Claude Code, Anthropic's coding assistant, for core parts of the underlying data pipeline. Session logs showed the tool being used to clean and format contact lists, including a batch of more than 100,000 Polish phone numbers, add country calling prefixes, and manage checking scripts tied to a network of proxy pools used to avoid detection while validating numbers at scale.

Scale and precision targeting

The operation processed roughly 885,000 phone numbers in total across multiple regional datasets. A German-language subset of 316,002 mobile numbers yielded 43,066 accounts, about 13.6 percent, confirmed as active cryptocurrency platform users through automated validation. That validation step is what separates this operation from generic scam calling: rather than cold calling at random and hoping for a hit, the operator could concentrate every subsequent effort exclusively on people already confirmed to hold crypto exchange or hardware wallet accounts worth targeting.

Rapid7 noted that this pre-validation dramatically improves the economics of the fraud, converting a low-yield mass phishing exercise into a targeted campaign against a pool of people already known in advance to be worth attacking. The AI-assisted data cleaning itself was not the sophisticated part of the operation. It was the unglamorous prerequisite work that made the genuinely sophisticated part, precision targeting at scale across nearly a million phone numbers, possible for a single operator to run.

Where the guardrail held, and where it did not

According to Rapid7's findings, Claude declined to assist when the operator asked for help building wallet-draining malware components, the piece of the operation specifically designed to directly steal funds from victims once they were compromised. That refusal forced the operator to switch to a different AI provider entirely and deploy a custom jailbreak prompt engineered to bypass safety mechanisms and get equivalent malicious code written elsewhere, outside Anthropic's own guardrails.

That split matters for how enterprises and vendors think about AI safety guardrails going forward. The refusal worked exactly as intended for the overtly malicious request, malware built specifically to steal money directly from a victim's wallet. It did essentially nothing to stop the same tool from performing data cleaning, formatting, and list management tasks that look identical to legitimate developer work and only become part of a crime once combined with everything else running on that exposed server.

The fraud mechanics behind the data prep

Once the operator had a validated list of confirmed crypto holders, the scheme layered multiple attack vectors on top of it: phishing emails generating fake support cases and verification codes, vishing calls citing validated account details to convincingly impersonate legitimate exchange support staff, and counterfeit mobile apps mimicking Trezor Suite, Ledger Live, and Exodus. The fake Trezor application would terminate the real software running on a device, display a fraudulent recovery phrase entry screen, and exfiltrate whatever was typed directly to a Telegram channel controlled by the operator.

Each of those individual steps closely resembles normal software and normal customer outreach on its own. It is the combination, powered by a validated target list an AI coding assistant helped assemble and refine, that turns them into a functioning theft pipeline capable of operating at real scale. That composability across ordinary looking parts is precisely what makes this class of abuse so hard to catch at the point of any single tool interaction or transaction.

Why this is a governance problem beyond one vendor

It is tempting to read this purely as an AI vendor content moderation story, and Anthropic's usage policies do prohibit exactly this kind of criminal use of its products. The more durable lesson for enterprise security teams, though, is that AI coding assistants now function as general purpose productivity tools inside criminal workflows the same way spreadsheets and scripting languages always have, and no amount of request-level filtering reliably catches a legitimate-looking data cleaning task performed in service of an illegitimate purpose.

Enterprises deploying their own internal AI coding assistants should assume the same basic dynamic applies inside their own walls: the tool will refuse an obviously malicious request outright, but will happily help an employee or contractor with a task that only becomes a genuine problem in a broader context the tool itself cannot see or evaluate. That reality argues strongly for monitoring built around data access patterns and downstream output use, not solely prompt-level content filtering at the point of the request.

The decision this puts on your desk

For CISOs, Operation ASTERIX previews how AI-assisted crime will actually show up in threat intelligence going forward: rarely as dramatic, obviously AI-generated malware, and far more often as ordinary AI productivity use quietly embedded inside an otherwise conventional fraud pipeline. Fraud and abuse teams at any company with a consumer facing product, not just cryptocurrency exchanges, should assume attackers targeting their users are already using AI tools to clean, validate, and prioritize target lists at a scale that manual work never made possible before now.

The practical response is twofold. Push threat intelligence and fraud monitoring vendors to detect the downstream signatures of AI-assisted targeting, like unusually high contact success rates against pre-validated accounts, and treat your own organization's AI tool usage logs as a genuine security telemetry source worth retaining and actively reviewing, not merely a productivity metric tracked for adoption reporting. The organizations that build that review capability now will have a real advantage the next time an exposed operator server surfaces a pipeline that quietly used their own product to get built.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#claude-code#cryptocurrency-fraud#rapid7#vishing#phishing#jailbreak#anthropic