Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak, and Atlantic — Threadlinqs Intelligence
As of 2026-07-26, Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak, and Atlantic is a high-severity phishing threat attributed to financially-motivated distributed cybercriminal groups operating wallet-drainer-as-a-service, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1708 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: financially-motivated distributed cybercriminal groups operating wallet-drainer-as-a-service · FINANCIAL
Chainalysis details "approval phishing," a cryptocurrency scam typology in which victims are socially engineered into granting malicious actors wallet-approval access, allowing scammers to drain funds
Approval phishing abuses standard, intended EVM wallet-permission functionality rather than a software vulnerability. Victims are socially engineered — often by a coached 'mentor' or support persona who directs them off regulated exchanges into self-custody using urgency and rehearsed investment narratives — into signing a transaction that looks minor but actually grants a scammer's address broad spending authority over their wallet. The three technical vectors documented across sourced research are: (1) the ERC-20 approve()/transferFrom() pattern, where a victim grants an unlimited allowance and the scammer later calls transferFrom() to drain tokens; (2) EIP-2612 permit() off-chain gasless-approval signatures, which leave no on-chain trace until the scammer executes the transfer, evading standard approval monitoring; and (3) the newer EIP-7702 SET_CODE (0x04) account-delegation transaction type, where victims are told they are performing a 'wallet upgrade,' 'security enhancement,' or 'AI assistant authorization' but are actually delegating execution authority to a malicious contract that can move funds without further prompts. NFT holders face an analogous setApprovalForAll abuse pattern.
The attack is increasingly commoditized: drainer-as-a-service kits (Inferno Drainer, Inferno Drainer Reloaded, Angel Drainer, Pink Drainer) and phishing-as-a-service platforms (Lighthouse) let low-skill affiliates deploy cloned dApp phishing pages for a cut (historically ~20-30%) of stolen proceeds. Inferno Drainer Reloaded (March-May 2025) stole over $9 million from 30,000+ wallets across Ethereum, BNB Smart Chain, Polygon, and Base using on-chain encrypted command-and-control, self-destructing contracts to dodge blacklists, and 'Red Pill' logic that behaves benignly during wallet-simulation checks (e.g., Rabby, MetaMask) and only executes the malicious drain after the victim signs -- exploiting the time-of-check/time-of-use (TOCTOU) gap between wallet-simulation state and live on-chain execution state, per ThreeSigma technical analysis; the same source documents phishing kits bundling obfuscated JavaScript that auto-generates and auto-fills EIP-7702 delegation payloads with a single pasted script line, and campaign infrastructure hosted on free platforms (GitHub Pages, Webflow) as well as compromised legitimate websites to inherit trust and evade domain-reputation blocklists. AI tooling is now a force multiplier: Chainalysis found AI-augmented scam operations generated 4.5x more revenue per operation ($3.2M vs $719K) than non-AI operations, and impersonation-scam severity/volume surged over 1400% and 600% respectively year over year, driven partly by AI-generated, constantly-rotating phishing content that defeats static detection.
At scale, Chainalysis attributes at least $14 billion in confirmed on-chain crypto scam revenue in 2025 (projected to exceed $17 billion as more addresses are attributed), with the average payment per scam address up 253% YoY ($782 to $2,764), and total approval-phishing losses since May 2021 estimated at $2.7 billion. Once drained, proceeds move through a documented laundering pipeline — reused consolidation wallets and spender contracts, cross-chain bridging, and Chinese-language laundering marketplaces such as Huione Guarantee — before cashing out at exchanges.
In response, Chainalysis and law-enforcement partners have run an escalating series of named disruption operations. Operation Disruption (a March 2024 pilot with Calgary Police Service) became Operation Spincaster (launched July 2024): an ecosystem-wide initiative spanning six countries (US, UK, Canada, Spain, Netherlands, Australia), 12 public-sector agencies, and 17 exchanges (including Binance and NDAX), generating 7,000+ investigative leads tied to roughly $162 million in losses and a new real-time exchange-screening API. Operation DeCloak (Delta, British Columbia, Canada, September 2024) examined 240 addresses tied to over $25 million in estimat
Target sectors: individual cryptocurrency holders, self-custody wallet users, cryptocurrency exchanges, retail investors, financial services
Target regions: united states of america, united kingdom, canada, spain, netherlands, australia, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1593, T1583, T1583, T1584, T1585, T1587, T1588, T1588, T1608, T1608