Skip to content
LIVE MARKETS
Loading market data …………………………
🌤
BREAKING
China delays moon landing mission to 2027 Historic volcanic eruptions and climate change impacts Mayors planning powers: England’s big shift in housing decisions Artemis II crew Congressional Space Medal of Honor award U.S.-Canada tariffs: why trade talks collapsed Crypto D&O insurance coverage gets explicit clarity from Corgi Bitcoin price forecast: Bitget CEO expects trading range at year-end Iran economic sanctions: why the U.S. is tightening the screw
Finance Wire

Crypto phishing campaign targets 885,000 phone numbers

A new scam targeting nearly a million people tries to steal cryptocurrency by mimicking legitimate wallet providers.

File photo illustrating this crypto phishing campaign report
Photo: Openverse contributor via Openverse (CC0)

Key Takeaways

  • Scammers are using text messages to trick investors into visiting fake wallet websites and handing over their crypto.
  • Nearly 885,000 phone numbers were targeted in this coordinated campaign discovered by cybersecurity firm Rapid7.
  • Check sender numbers carefully, never click unsolicited links, and only visit wallet sites by typing the address yourself.

A major cryptocurrency phishing campaign has been uncovered targeting 885,000 phone numbers, according to cybersecurity firm Rapid7. The scam uses text messages to impersonate trusted wallet providers and trick investors into entering login credentials on counterfeit websites.

This represents one of the largest coordinated efforts to harvest cryptocurrency holdings through mobile phones in recent months.

How the crypto phishing campaign actually works

The attackers send text messages that appear to come from legitimate cryptocurrency wallet companies. The message typically contains urgent language (account compromised, unusual activity detected, verification needed) and a link.

When someone clicks the link, they land on a fake website that looks nearly identical to the real wallet provider. The design, colours, logos, everything matches. Victims enter their recovery phrases, passwords, or private keys thinking they’re logging into their genuine account.

Within minutes, the scammers have full access to the wallet and can transfer out all holdings. There is no reversal mechanism in cryptocurrency: once the crypto moves, it’s gone.

What makes this campaign notable is the scale and precision. Targeting 885,000 phone numbers suggests the attackers either purchased a bulk list of crypto investors from a previous data breach, or they’re using common number patterns to cast a wide net across wealthy demographics.

Why this is happening now and what to watch

Cryptocurrency theft has shifted away from pure hacking toward social engineering and phishing. It’s cheaper, faster, and requires no technical sophistication. Text messages are particularly effective because they feel personal and urgent in a way that email doesn’t.

In my experience covering crypto fraud, the moment one major phishing template succeeds, copycat versions flood the market. We’re likely to see dozens of variations on this same approach targeting different wallet providers over the coming weeks.

The discovery by Rapid7 means the campaign is now public knowledge, which typically causes adoption to drop. However, the attackers have likely already achieved their goal with some portion of the 885,000 targets. Even a 0.1% success rate on that scale generates substantial stolen assets.

How do I know if a text about crypto is real?

Legitimate wallet companies rarely text you first about account issues. They’ll notify you inside the app itself. Real wallet providers never ask for your recovery phrase or private key via text or email. Never click links in unsolicited messages: instead, type the official website address directly into your browser yourself, or open the official app you already have installed.

What this means for you

Whether you hold cryptocurrency on a phone wallet, exchange account, or hardware device, phishing attempts will eventually reach you. The good news is that awareness and a simple process prevent almost all successful attacks.

  • Be sceptical of any text or email claiming urgent action is needed on your account, especially if you weren’t expecting it. Wallet providers don’t initiate contact this way.
  • Never enter credentials, seed phrases, or private keys on any website you reached by clicking a link. Always type the address yourself or use the official app.
  • If you use a phone wallet, consider moving significant holdings to a hardware wallet (a physical device like Ledger or Trezor) where private keys never touch the internet.

For detailed guidance on recognising crypto fraud and protecting different types of wallets, explore Thewealthora’s full guides to cryptocurrency security and avoiding investment scams.

Original reporting on this crypto phishing campaign: Cointelegraph.

More on crypto phishing campaign from Thewealthora

Originally reported by Cointelegraph. Facts verified; analysis and wording are Thewealthora’s own.

Was this helpful?

Arpit Soni

The Thewealthora desk covers markets, money and personal finance, with zero jargon and every claim sourced.

Leave a Reply

Your email address will not be published. Required fields are marked *