Threat reportPhishingTL-2026-0837

Approval Phishing: Wallet-Draining Crypto Scams via Malicious Token Approvals (approve/permit/setApprovalForAll)

highACTIVE

Approval Phishing (TL-2026-0837), also tracked as Approval phishing, is a high-severity phishing campaign, first published 2026-06-17. It is attributed to Pig-butchering with medium confidence, affects Ethereum / EVM ecosystem ERC-20 token allowance model (approve /, maps to 12 MITRE ATT&CK techniques (T1204, T1213, T1528), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
1Pig-butchering
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0837

Threat ID
TL-2026-0837
Also known as
Approval phishing, Token approval phishing, Wallet drainer, ice phishing, Permit phishing, setApprovalForAll phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
Pig-butchering
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
retail investors, cryptocurrency, financial, individuals, decentralized finance
Target regions
United States, United Kingdom, Canada, Europe, Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in Approval Phishing

Malware and tooling: Pink Drainer, Angel Drainer, Inferno Drainer, Wallet drainer-as-a-service kit

How Approval Phishing works

Approval phishing tricks a victim into signing what looks like a minor wallet interaction that actually grants an attacker-controlled address an on-chain spending allowance, letting the scammer drain the wallet's tokens at will. On-chain scams reached at least $14 billion (likely $17 billion) in 2025, with the average payment to a single scam address up 253% year-over-year and AI-augmented scams 4.5x more profitable.

Approval phishing is an on-chain social-engineering technique that abuses the legitimate token-authorization model of EVM (and TRON) smart-contract platforms rather than any software vulnerability. Instead of stealing a private key, the attacker convinces a victim to authorize a transaction or sign an off-chain message that grants the attacker's address an allowance over the victim's tokens. Once the allowance exists, the attacker can call transferFrom at any time to move funds out of the victim's wallet — instantly, or by lurking until the victim deposits fresh funds.

The abuse centers on three approval primitives. For ERC-20 tokens the attacker induces a call to approve(address,uint256) (selector 0x095ea7b3) or increaseAllowance, typically requesting the maximum uint256 value (0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff) so the allowance is effectively unlimited and persists until revoked. For ERC-721/ERC-1155 NFTs the attacker induces setApprovalForAll(address,bool) (selector 0xa22cb465), which authorizes the operator to move every token in a collection. The most dangerous variant abuses EIP-2612 permit (selector 0xd505accf) and Uniswap's Permit2 standard: the victim signs an off-chain EIP-712 message — never a visible on-chain transaction — and the attacker submits it on-chain to obtain the allowance, then drains in the same bundle. Observed drainer kits chain a permit and transferFrom atomically (e.g., DELEGATECALL through Multicall3) so a single signature grants unlimited USDC/USDT approval and immediately distributes stolen funds, with no protocol exploit or flash loan required.

The social-engineering wrapper is usually a pig-butchering / romance-investment scam: victims are coached off regulated exchanges into self-custody wallets, walked through 'connecting' to a fake high-yield investment or trading dApp by a 'mentor' figure using rehearsed lines and artificial urgency, and told the approval is a routine step to 'activate' trading. The lure surfaces as a bank red flag when customers with no crypto history suddenly wire large sums.

Law-enforcement and industry response has been substantial: Operation Spincaster (Chainalysis-led, launched July 2024) processed over 7,000 leads and addressed roughly $162M in losses across sprints in six countries, against an estimated $2.7B stolen via approval phishing between May 2021 and July 2024. Operation Atlantic (announced April 9, 2026; UK NCA with US Secret Service, Ontario Provincial Police, Ontario Securities Commission, Chainalysis and TRM Labs) identified more than 20,000 victim wallet addresses across 30+ countries, directly contacted over 3,000 victims, froze more than $12M in proceeds and traced a further $45M. Operation DeCloak addressed approval-phishing fund freezes/seizures in Delta, Canada.

MITRE ATT&CK techniques used in TL-2026-0837

Execution

T1204 User Execution

Collection

T1213 Data from Information Repositories

Credential Access

T1528 Steal Application Access Token

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Approval Phishing

  • Ethereum / EVM ecosystem — ERC-20 token allowance model (approve / increaseAllowance)
    Vulnerable versions: ERC-20 approve(address,uint256); EIP-2612 permit; Uniswap Permit2
  • Ethereum / EVM ecosystem — ERC-721 / ERC-1155 NFT operator approvals (setApprovalForAll)
    Vulnerable versions: setApprovalForAll(address,bool)
  • Tether — USDT (ERC-20 and TRC-20)
    Vulnerable versions: USDT-ERC20; USDT-TRC20

Remediation for Approval Phishing

Immediate actions

  • Review and revoke all unnecessary token allowances using an approval manager (e.g., revoke.cash or the wallet's built-in approval/permission manager); prioritize unlimited (MaxUint256) approvals and any setApprovalForAll operators
  • Before signing, decode calldata: verify the spender address (second 32-byte slot, left-padded) against the intended dApp and confirm the amount is not 0xffff...ff
  • Treat off-chain signature requests (permit / Permit2 / EIP-712) with the same scrutiny as transactions — verify spender, amount, token, and contract address
  • If actively scammed, race the attacker by submitting an approve(spender,0) / revocation before the next transferFrom

Workarounds

  • Set finite, per-transaction allowances instead of unlimited approvals where the dApp supports it
  • Periodically audit approvals and revoke stale operators/spenders

Longer-term hardening

  • Use a dedicated hot wallet with minimal balances for unknown dApp interactions; keep core funds in a separate cold/hardware wallet that never connects to dApps
  • Enable wallet transaction-simulation / approval-warning features and clear-signing on hardware wallets
  • Educate users that legitimate platforms never require unlimited approvals to an unknown address, and that 'mentors' coaching off regulated exchanges into self-custody are a scam signature

Weaknesses (CWE) in Approval Phishing

CWE-1021, CWE-862, CWE-451

Timeline of Approval Phishing

  • Start of Chainalysis tracking window for approval-phishing losses later estimated at ~$2.7B (through July 2024).
  • During a Spincaster sprint, partners directly contacted a victim who revoked the malicious approval before a six-figure sum was drained.
  • Chainalysis launches Operation Spincaster, a public-private initiative targeting approval-phishing and pig-butchering scams across six countries (US, UK, Canada, Spain, Netherlands, Australia).
  • Tether, working with Chainalysis and the DOJ, froze approximately $225M in USDT held in perpetrators' wallets tied to a Southeast Asia pig-butchering compound.
  • On-chain scams reach at least $14B (likely $17B) for 2025; average payment per scam address up 253% YoY; AI-augmented scams 4.5x more profitable.
  • Law enforcement directly contacts more than 3,000 identified Operation Atlantic victims; one UK victim reported a loss exceeding £52,000.
  • Operation Atlantic freezes more than $12M in suspected criminal proceeds and traces a further $45M in stolen crypto.
  • Operation Atlantic announced: NCA/US Secret Service/Ontario Provincial Police/OSC/Chainalysis/TRM identify 20,000+ victim wallets across 30+ countries during a week-long action.
  • Threat documented in Threadlinqs Intelligence Platform as TL-2026-0837.
  • Chainalysis publishes explainer 'What Is Approval Phishing? How Scammers Drain Crypto Wallets'.

Sources cited for Approval Phishing

Detection coverage for TL-2026-0837

As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0837 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats