
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Cybersecurity firm Rapid7 uncovered Operation ASTERIX, a large-scale crypto phishing campaign using AI coding assistants to develop malicious tools, automate attacks, and bypass security safeguards. The operation targeted nearly 900,000 phone numbers, deploying counterfeit wallet apps and phishing tactics to steal users' cryptocurrency recovery phrases and funds.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event explicitly involves AI systems in the attackers' workflow, including AI coding assistants used to create and obfuscate phishing tools and malware. The campaign has already caused harm by stealing wallet recovery phrases, which is a direct harm to property and communities. The AI system's role is pivotal in enabling the sophisticated fraud operation. Hence, the event meets the criteria for an AI Incident due to realized harm caused by AI-assisted malicious use.[AI generated]