Crypto Phishing Campaign Targeted 885,000 Phone Numbers, Rapid7 Labs Analysis Shows
Key Takeaways
- •The reported campaign targeted 885,000 phone numbers, but that figure reflects outreach rather than verified theft or victim counts.
- •Rapid7 Labs described the operation as a crypto fraud scheme that combined vishing and phishing tactics.
- •The attack relied on impersonation and deceptive prompts rather than a direct exploit of wallets, protocols, or smart contract code.
- •The broad use of phone calls and text messages made the target list significant because it expanded the number of people exposed to fraudulent contact.
- •The disclosure underscores the risks crypto users face because transactions are difficult to reverse once funds are transferred.

A cybersecurity firm has disclosed a crypto phishing campaign that drew on a pool of 885,000 phone numbers, according to reporting on the disclosure. The figure describes the scale of the campaign's outreach, not a confirmed total of stolen funds.
What the cybersecurity firm reported
The claim originates from a cybersecurity firm's research into a crypto fraud operation. The reported target pool of 885,000 phone numbers represents the campaign's stated reach.
The activity is documented in a Rapid7 Labs analysis of the operation, which frames the scheme as a crypto fraud effort combining vishing and phishing tactics — fraudulent outreach conducted by phone calls and by deceptive messages. The 885,000 figure reflects targeting, not a verified count of victims or confirmed theft.
How the campaign appears to have worked
The campaign is categorized as phishing rather than a direct wallet or protocol exploit. Phishing relies on impersonation and deceptive prompts to extract credentials or wallet access, an approach distinct from on-chain attacks that abuse smart contract code.
Phone numbers are useful to attackers because they enable direct outreach at scale through calls and text messages. That distribution channel is what makes a target list numbering in the hundreds of thousands significant, since it widens the pool of people who may receive a fraudulent prompt.
This mechanism differs from the on-chain incidents that drove bridge exploits and other large crypto losses in 2026, where attackers targeted code and infrastructure rather than individuals directly.
Why the report matters for crypto users
The scale is the main reason the report is newsworthy. A target list on that order suggests broad-scale outreach rather than a narrowly focused operation.
Crypto users are frequent phishing targets because transactions are difficult or impossible to reverse once funds move. Impersonation messages tied to exchange accounts or wallets can pressure recipients into surrendering access before they verify the source.
For platforms and users alike, the disclosure underscores the exposure that comes with widely circulated contact data. Regulators including the U.S. Securities and Exchange Commission have long warned investors about fraud schemes that rely on unsolicited outreach, a category into which this reported campaign fits.
This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.