- Security firm Rapid7 says it found a phishing operation built around a list of about 885,000 phone numbers.
- Targets are sent to convincing copies of wallet provider websites and asked to connect a wallet or enter a .
- We could not access Rapid7’s own write-up, so the detail below rests on Cointelegraph’s report plus how campaigns of this shape normally work.
A text arrives saying there’s a problem with your wallet, or a pending transaction to approve. It looks like it came from a company you actually use. According to the cybersecurity firm Rapid7, roughly 885,000 phone numbers have been lined up for messages of that kind.
Anyone can receive one of these. A list of 885,000 numbers is not a list of crypto holders: it is a list of phone numbers, bought or scraped, sent out on the assumption that some small fraction of the people on it own crypto. The messages are convincing because they are meant to be, and the only reliable defence is knowing what a real wallet provider will and won’t ask you for.
What the campaign appears to do

Cointelegraph reports that the operation redirects people to fake wallet provider websites in order to reach their holdings. That is the standard shape for this kind of thing, and it usually runs in stages rather than one jump.
A message lands with a short link. The link goes to an intermediate page, often on a domain that means nothing, which checks whether the visitor looks like a real phone rather than a security researcher’s scanner. If it passes, the visitor is bounced on to a page dressed up as the login or support screen of a well-known wallet. If it doesn’t, the visitor gets a blank page or something harmless, which is one reason these operations can run for weeks before anyone documents them.
The final page asks for one of two things. Either it wants your recovery phrase, the twelve or twenty-four words that regenerate your wallet, typed into a box that looks like a legitimate restore screen. Or it asks you to connect your wallet and then approve a transaction that hands over spending permission for your .
The line that never moves
No genuine wallet provider will ever ask for your recovery phrase. Not support, not a security team, not a verification page, not an app update. Those words exist so that you alone can restore the wallet, and anyone who has them has the wallet. There is no situation in which a real company needs them, which makes the request itself the tell, regardless of how good the page looks.
The approval prompts are harder, because a connection request is a normal part of using crypto. What’s worth reading is the wording. A request to view your address or prove ownership by signing a message costs you nothing. A request that mentions approving, permitting or setting an allowance for a token is asking for permission to move that token, and unlimited approvals are the usual mechanism behind a wallet emptying minutes after someone clicked. Most wallets show the contract address and the permission being granted before you sign. Slowing down at that screen is the whole game.
What we can and can’t stand behind
We could not reach Rapid7’s original research, so this piece works from Cointelegraph’s account of it. The 885,000 figure is Rapid7’s, as reported there, and we can’t independently confirm how the count was reached, whether those numbers are UK, US or global, or how many people actually received a message rather than simply appearing on a list. Which wallet brands were impersonated hasn’t been reported either.
Those gaps matter for judging scale. They don’t change the practical part: the mechanics of a fake wallet page are the same whether the list runs to 885,000 numbers or 85,000.
If you get one of these in the UK
Suspicious texts can be forwarded free to 7726, which routes to your mobile network’s reporting service. Scam websites can be reported to the National Cyber Security Centre at report@phishing.gov.uk. If money has already gone, Action Fraud takes reports online or on 0300 123 2040, and it’s worth telling your bank and, if the funds passed through one, the exchange as well.
Recovery is rare once a transaction confirms, which is uncomfortable but honest. Reporting still matters, because it is how the domains get taken down and how the scale gets measured.
If you’re weighing up how you hold your coins in the first place, our guide to self-custody covers the trade-offs, including what a recovery phrase is actually for.
What to watch
Whether Rapid7 publishes the impersonated brands. Naming them would let those companies warn their own users directly, which is considerably more effective than general advice.
Beyond that, whether any wallet provider responds. Firms in this position tend to say very little publicly about impersonation campaigns, and the ones that do warn customers early are usually the ones that limit the damage.