# Approval Phishing: Wallet-Draining Crypto Scams via Malicious Token Approvals (approve/permit/setApprovalForAll)

> Approval phishing tricks a victim into signing what looks like a minor wallet interaction that actually grants an attacker-controlled address an on-chain spending allowance, letting the scammer drain the wallet's tokens at will. On-chain scams reached at least $14 billion (likely $17 billion) in 2025, with the average payment to a single scam address up 253% year-over-year and AI-augmented scams 4.5x more profitable.

- **Published:** 2026-06-17T00:00:00Z
- **Last reviewed:** 2026-06-17T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0837
- **ID:** TL-2026-0837
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Pig-butchering
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Approval phishing is an on-chain social-engineering technique that abuses the legitimate token-authorization model of EVM (and TRON) smart-contract platforms rather than any software vulnerability. Instead of stealing a private key, the attacker convinces a victim to authorize a transaction or sign an off-chain message that grants the attacker's address an allowance over the victim's tokens. Once the allowance exists, the attacker can call transferFrom at any time to move funds out of the victim's wallet — instantly, or by lurking until the victim deposits fresh funds.

The abuse centers on three approval primitives. For ERC-20 tokens the attacker induces a call to approve(address,uint256) (selector 0x095ea7b3) or increaseAllowance, typically requesting the maximum uint256 value (0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff) so the allowance is effectively unlimited and persists until revoked. For ERC-721/ERC-1155 NFTs the attacker induces setApprovalForAll(address,bool) (selector 0xa22cb465), which authorizes the operator to move every token in a collection. The most dangerous variant abuses EIP-2612 permit (selector 0xd505accf) and Uniswap's Permit2 standard: the victim signs an off-chain EIP-712 message — never a visible on-chain transaction — and the attacker submits it on-chain to obtain the allowance, then drains in the same bundle. Observed drainer kits chain a permit and transferFrom atomically (e.g., DELEGATECALL through Multicall3) so a single signature grants unlimited USDC/USDT approval and immediately distributes stolen funds, with no protocol exploit or flash loan required.

The social-engineering wrapper is usually a pig-butchering / romance-investment scam: victims are coached off regulated exchanges into self-custody wallets, walked through 'connecting' to a fake high-yield investment or trading dApp by a 'mentor' figure using rehearsed lines and artificial urgency, and told the approval is a routine step to 'activate' trading. The lure surfaces as a bank red flag when customers with no crypto history suddenly wire large sums.

Law-enforcement and industry response has been substantial: Operation Spincaster (Chainalysis-led, launched July 2024) processed over 7,000 leads and addressed roughly $162M in losses across sprints in six countries, against an estimated $2.7B stolen via approval phishing between May 2021 and July 2024. Operation Atlantic (announced April 9, 2026; UK NCA with US Secret Service, Ontario Provincial Police, Ontario Securities Commission, Chainalysis and TRM Labs) identified more than 20,000 victim wallet addresses across 30+ countries, directly contacted over 3,000 victims, froze more than $12M in proceeds and traced a further $45M. Operation DeCloak addressed approval-phishing fund freezes/seizures in Delta, Canada.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1598 Phishing for Information
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1684.001 Impersonation
- T1528 Steal Application Access Token
- T1213 Data from Information Repositories
- T1657 Financial Theft

## Sources

- [What Is Approval Phishing? How Scammers Drain Crypto Wallets](https://www.chainalysis.com/blog/what-is-approval-phishing/)
- [Operation Spincaster: Disrupt & Prevent Losses in Crypto Scams](https://www.chainalysis.com/blog/operation-spincaster/)
- [How Public-Private Collaboration Is Freezing Crypto Scam Proceeds (Operation Atlantic)](https://www.chainalysis.com/blog/operation-atlantic-freezing-crypto-scam-proceeds/)
- [Operation Atlantic disrupts more than $45 million in cryptocurrency fraud, freezes $12 million in stolen funds](https://www.secretservice.gov/newsroom/releases/2026/04/operation-atlantic-disrupts-more-45-million-cryptocurrency-fraud-freezes)
- [TRM Labs Supports Operation Atlantic: USD 12 Million Frozen and 20,000 Victims Identified](https://www.trmlabs.com/resources/blog/trm-labs-supports-operation-atlantic-usd-12-million-frozen-and-20-000-victims-identified-in-international-crackdown-on-crypto-scammers)
- [Detecting Token Approval Phishing in Calldata](https://ghostkit.net/techniques/approval-phishing-detection)
- [USDC Permit Phishing Drain](https://www.darknavy.org/web3/exploits/usdc-permit-phishing-drain/)
- [ERC-20 Authorization: How Permit and Permit2 Work, Risks, and Key Differences](https://www.gate.com/learn/articles/a-deep-dive-into-the-erc-20-authorization-model-how-permit-and-permit2-work-their-risks-and-key-differences/8707)
- [Understanding Ethereum Token Approvals](https://support.ledger.com/article/Ethereum-Token-Approvals-Explained)
- [Avoiding Approval Phishing and Wallet Drainers: A Consumer Checklist](https://www.coca.xyz/post/avoiding-approval-phishing-and-wallet-drainers-a-consumer-checklist)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0837
