Over the past seven days, I have identified several serious attack vectors that require close attention from the crypto community. From large-scale phishing based on stolen phone databases to the infection of critical development infrastructure components, threats are becoming increasingly sophisticated and targeted.

Operation "Asterix": The Hunt for Seed Phrases

I managed to analyze data on a large-scale phishing campaign in which attackers gained access to a database of approximately 885,000 phone numbers of crypto investors worldwide. The attack scheme looks classic, but the execution is top-tier. Victims received calls posing as tech support or were sent fake emails imitating legitimate services like Crypto.com. The main goal is to lure the user to a phishing site or force them to install a fake app that visually copies the interfaces of Ledger, Trezor, or Exodus to steal seed phrases.

What is particularly alarming is the automation of the process. Hackers used scripts to mass-check numbers against the databases of major exchanges. The effectiveness turned out to be frighteningly high: in a sample from Germany, matches amounted to 13.6% (43,066 real investors), and more than 5,500 confirmed Binance accounts were queued for priority attacks. The largest fragment of stolen data contains 316,002 numbers of German citizens, with residents of the USA, UK, Hong Kong, and Ledger clients also on the lists. Note that AI tools were actively used to generate phishing content, making attacks more personalized and dangerous.

Fake AML Checkers: A New Trap for Wallets

Another scheme I tracked is the creation of fake AML services for checking the "purity" of crypto wallets. Scammers copy the design of legitimate platforms like AMLBot or use neutral brands. The trap triggers when the site requests permission to connect a wallet for "scanning." After that, an analysis process is simulated, and the victim receives an encouraging result: "Clean, low risk." However, under the guise of paying a fee or during the connection process, the user is tricked into signing a transaction that grants a malicious smart contract the right to withdraw funds. Scammers use the same website template, only changing the logos.

The Rust Ecosystem Under Attack: The arrayref Incident

The most alarming incident, in my opinion, is the compromise of the developer account of the popular Rust package arrayref. Attackers injected malicious code that executed directly during project compilation. Given that arrayref has over 245 million downloads and is used in blockchain tools for Ethereum and Solana, the potential scale of infection is enormous. The attack included the injection of a dependency on a malicious package, proc-macro1 (disguised as the legitimate proc-macro2), and a fake build.rs script downloaded a loader adapted to the victim's OS. The trojan collected system information and stole password databases from browsers. Experts note the similarity of the infrastructure to attacks on Mastra and Axios, which are linked to the North Korean group Sapphire Sleet.

Compromise of 14,500 Dahua Cameras and the Manic Trojan

I also analyzed Operation CameraSwarm, during which 14,530 Dahua surveillance cameras were compromised in 35 days, primarily in the networks of providers in Russia and Ukraine. Hackers used three vectors: brute-forcing passwords on port 37777, exploiting outdated vulnerabilities via p2pwn, and intercepting control through serial numbers. I strongly recommend camera owners check for a hidden p2pwn account and update their firmware.

Additionally, a Manic trojan for Android was discovered, targeting 169 apps, including banking and cryptocurrency ones. Its uniqueness lies in a backup data transmission mechanism: if the smartphone is offline, the virus transfers data to other infected devices via Wi-Fi Direct or Bluetooth, creating a mesh network to bypass blocks.

My verdict: We are witnessing a consolidation of efforts by cybercriminals and their shift to mass, automated attacks using AI. Crypto investors need to exercise maximum vigilance: never enter seed phrases on suspicious sites and never sign transactions whose purpose is not fully understood. Security is not a one-time action but an ongoing process.