Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

Rapid7 found the scammer's exposed workspace, proof that switching AI models routed around Claude's refusal, and a Windows build that broke in the process.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 20, 2026
in Security & Hacks
0 0
Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

Photo by Anete Lusina from Pexels/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle
  • Rapid7 Labs found a crypto-phishing operation’s entire workspace exposed on a misconfigured server, including logs of Claude Code refusing a code-obfuscation request and the operator switching to a different model, Kimi, to get it done anyway.
  • The same operation’s Windows build of its fake Trezor Suite app never worked, broken by a config file that only recognized macOS.
  • The pipeline had already validated 43,066 accounts out of 316,002 German phone numbers before Rapid7 found it, a 13.6% hit rate.

When the operator behind a large crypto-phishing campaign asked Claude Code to obfuscate malicious code, Claude refused. The operator switched to Kimi, built by Moonshot AI, and got it done there instead, according to a technical report Rapid7 Labs published this week.

Rapid7 Labs recently uncovered a crypto scammer’s working environment via a misconfigured web directory, exposing raw phone-number datasets, phishing panels, voice-dialing scripts, counterfeit wallet builds, and more.

👉 Full technical analysis here: https://t.co/9dLi1OCvNb pic.twitter.com/kbjbSFA3sv

— Rapid7 (@rapid7) August 17, 2026

The refusal didn’t stop the operation. It just moved the work to a different model. But it wasn’t free, either: the same operator’s Windows build shipped broken, its theft code disabled by a leftover macOS-only config setting. Something slipped in the handoff between tools.

Guardrails Acted as Friction, Not a Wall

AI guardrails here acted less like a lock and more like friction, real, but nowhere close to enough to stop a determined operator on its own. Inside Anthropic’s own ecosystem, that friction has held up better: during a recent Ethereum/USDT contract audit, Claude Fable 5 fell back to the more restricted Opus 4.8 once the questions turned toward exploitability. Operation ASTERIX shows what happens once a user leaves that ecosystem instead of staying inside it: the operator didn’t wait around for a fallback model, it just went to a different company’s product. What actually shut the operation down wasn’t Claude’s refusal. It was Rapid7 stumbling onto an exposed, unauthenticated web directory that handed over the operator’s entire toolkit and logs.

This tracks a wider pattern, one Anthropic itself is trying to get ahead of. Anthropic disclosed last September that Claude Code carried out an estimated 80-90% of a state-linked espionage campaign autonomously before it was disrupted, and it has since backed Project Glasswing, a defensive push meant to find critical vulnerabilities before criminals do. A malware strain called OkoBot, documented since January, uses a similar trick to Operation ASTERIX’s fake wallet apps: hijacking Electron-based wallet software to show a fake recovery-phrase screen. Criminals building on commercial AI assistants, and routing around them the moment they refuse, isn’t new anymore.

The Jailbreak Still Carrying Claude’s Fingerprints

The jailbreak prompt sent to Kimi ran thousands of words, built around a fictional persona named “ENI” and a trigger phrase, “cold coffee, warm LO, I can’t lose him,” meant to override safety responses. It still contained Claude-specific system tags, carried over from whatever was used against Claude. Kimi is a different model from a different company. Pasting Claude’s own internal framing into it does nothing there. It reads as a copy-paste error, not a calibrated attack.

885,000 Phone Numbers, One Exposed Server

885,000 phone numbers across 54 countries sat on the exposed server. A Go script checked them against Crypto.com’s passkey endpoint using 300 threads and rotating residential proxies. Validated numbers fed a vishing operation on Asterisk and 3CX phone systems, source of the “ASTERIX” codename, and counterfeit Trezor, Ledger Live, and Exodus apps that sent stolen seed phrases to Telegram bots.

Rapid7 says it notified Apple’s security team and acted against the infrastructure while the operation was still active. No threat actor has been named, and no loss or victim figure has been made public. The open question isn’t whether AI models should refuse obfuscation requests. It’s whether a user jumping between models mid-task, especially while copy-pasting one company’s safety language into another’s product, is itself a signal worth watching for.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Security & Hacks

Revolut Suspected of Leaking Customer Data After Fake Government Request

by Akil Prasath LV
September 12, 2026

Key Facts Revolut is suspected of responding to a spoofed government data request with real customer records. Exposed data reportedly...

Read moreDetails
Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

August 31, 2026
Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

August 28, 2026
Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

August 27, 2026
Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

August 27, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

August 18, 2026
Next Post
ICX, SCRT and STORJ Are Leaving Binance for Three Unrelated Reasons

ICX, SCRT and STORJ Are Leaving Binance for Three Unrelated Reasons

CZ Says Trump’s Hyperliquid Push Could Benefit U.S. Perp DEXs

CZ Calls Trump’s Hyperliquid Push ‘Hugely Positive’ for Crypto

Recommended

  • All
  • Crypto News Today
Hyperion DeFi Retires All Legacy Debt and Begins Share Buybacks Funded by HYPE Sales

Hyperion DeFi Retires All Legacy Debt and Begins Share Buybacks Funded by HYPE Sales

October 3, 2026
SBI Holdings Completes Full Acquisition of Bitbank, Japan's Crypto Exchange

SBI Holdings Completes Full Acquisition of Bitbank, Japan’s Crypto Exchange

October 3, 2026
SEC Proposes Custody Framework Letting Advisers and Funds Hold Crypto Assets Directly

SEC Proposes Custody Framework Letting Advisers and Funds Hold Crypto Assets Directly

October 3, 2026

JPMorgan Launches Auto Callable Notes Linked to Spot Bitcoin and Ether ETFs

October 3, 2026
Evernorth Shareholders Approve Armada Merger, Clearing Path to a Nasdaq XRP Listing

Evernorth Shareholders Approve Armada Merger, Clearing Path to a Nasdaq XRP Listing

October 3, 2026
Treasury Sanctions Russia-Linked A7 Network Over $179 Billion in Stablecoin Flows

Treasury Sanctions Russia-Linked A7 Network Over $179 Billion in Stablecoin Flows

October 3, 2026
Greywick Digital Signs MOU With Litecoin Foundation to Deploy cLTC on Canton Network

Greywick Digital Signs MOU With Litecoin Foundation to Deploy cLTC on Canton Network

October 3, 2026
Walapay Raises $4.6 Million Seed Round to Expand Global Payments Infrastructure

Walapay Raises $4.6 Million Seed Round to Expand Global Payments Infrastructure

October 3, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • BNB Plus Corp Pivots From BNB Treasury to Blockchain and AI Infrastructure
  • Hyperion DeFi Retires All Legacy Debt and Begins Share Buybacks Funded by HYPE Sales
  • SBI Holdings Completes Full Acquisition of Bitbank, Japan’s Crypto Exchange

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • Uncategorized
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.