Loading market data...

Rapid7 Flags AI-Powered Phishing Campaign Targeting Crypto Recovery Phrases

Rapid7 Flags AI-Powered Phishing Campaign Targeting Crypto Recovery Phrases

Rapid7 has uncovered a phishing campaign it calls Operation ASTERIX, which uses AI-powered tools to steal crypto wallet recovery phrases. The discovery underscores a growing threat: attackers are now using AI to craft more convincing lures aimed at the keys to users' funds.

How the AI-powered lures work

The campaign leverages AI to generate phishing messages that mimic legitimate communications, making them harder to spot. The goal is to trick users into handing over their recovery phrases — the seed words that grant full control of a wallet. Unlike a password, a recovery phrase can't be reset, so once it's compromised, the funds are gone.

Why recovery phrases are the prize

Recovery phrases are the master keys to crypto wallets. Anyone who gets them can drain an account without needing a password or two-factor authentication. That makes them a prime target for phishing, and AI gives attackers a way to scale up their efforts while keeping the messages believable.

The pressure on exchanges

The discovery highlights the need for enhanced security measures at exchanges. As AI-driven phishing becomes more common, exchanges must improve detection and user education. The finding also serves as a warning to users to be wary of unsolicited messages asking for seed phrases — no legitimate service will ever request them.

Rapid7's report doesn't specify which exchanges or users were targeted, but the implications are broad. With AI tools now in the hands of phishers, the bar for what counts as a convincing scam has risen. The next step is for exchanges to adapt their defenses accordingly, and for users to treat every request for a recovery phrase as a red flag.