Threat reportPhishingTL-2026-1708

Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak, and Atlantic

highACTIVE

Approval Phishing (TL-2026-1708), also tracked as Wallet-Drainer Scam, is a high-severity phishing campaign, first published 2026-07-26. It has no confirmed attribution, affects Ethereum Virtual Machine (EVM) Ecosystem ERC-20 approve() /, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1070), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1708

Threat ID
TL-2026-1708
Also known as
Wallet-Drainer Scam, Token-Approval Scam, Permit Phishing, Wallet-Approval Scam
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
individual cryptocurrency holders, self-custody wallet users, cryptocurrency exchanges, retail investors, financial services
Target regions
united states of america, united kingdom, canada, spain, netherlands, australia, Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in Approval Phishing

Malware and tooling: Angel Drainer, Chainalysis Reactor / Chainalysis Data Solutions, Inferno Drainer, Inferno Drainer Reloaded, On-chain encrypted command-and-control channel, Pink Drainer

How Approval Phishing works

Chainalysis details "approval phishing," a cryptocurrency scam typology in which victims are socially engineered into granting malicious actors wallet-approval access, allowing scammers to drain funds via transactions that appear minor but contain hidden implications. The report covers law-enforcement and private-sector disruption operations (Spincaster, DeCloak, Atlantic) that froze and traced tens of millions of dollars in proceeds amid a broader on-chain scam ecosystem generating an estimated $14-17 billion in 2025.

Approval phishing abuses standard, intended EVM wallet-permission functionality rather than a software vulnerability. Victims are socially engineered — often by a coached 'mentor' or support persona who directs them off regulated exchanges into self-custody using urgency and rehearsed investment narratives — into signing a transaction that looks minor but actually grants a scammer's address broad spending authority over their wallet. The three technical vectors documented across sourced research are: (1) the ERC-20 approve()/transferFrom() pattern, where a victim grants an unlimited allowance and the scammer later calls transferFrom() to drain tokens; (2) EIP-2612 permit() off-chain gasless-approval signatures, which leave no on-chain trace until the scammer executes the transfer, evading standard approval monitoring; and (3) the newer EIP-7702 SET_CODE (0x04) account-delegation transaction type, where victims are told they are performing a 'wallet upgrade,' 'security enhancement,' or 'AI assistant authorization' but are actually delegating execution authority to a malicious contract that can move funds without further prompts. NFT holders face an analogous setApprovalForAll abuse pattern.

The attack is increasingly commoditized: drainer-as-a-service kits (Inferno Drainer, Inferno Drainer Reloaded, Angel Drainer, Pink Drainer) and phishing-as-a-service platforms (Lighthouse) let low-skill affiliates deploy cloned dApp phishing pages for a cut (historically ~20-30%) of stolen proceeds. Inferno Drainer Reloaded (March-May 2025) stole over $9 million from 30,000+ wallets across Ethereum, BNB Smart Chain, Polygon, and Base using on-chain encrypted command-and-control, self-destructing contracts to dodge blacklists, and 'Red Pill' logic that behaves benignly during wallet-simulation checks (e.g., Rabby, MetaMask) and only executes the malicious drain after the victim signs -- exploiting the time-of-check/time-of-use (TOCTOU) gap between wallet-simulation state and live on-chain execution state, per ThreeSigma technical analysis; the same source documents phishing kits bundling obfuscated JavaScript that auto-generates and auto-fills EIP-7702 delegation payloads with a single pasted script line, and campaign infrastructure hosted on free platforms (GitHub Pages, Webflow) as well as compromised legitimate websites to inherit trust and evade domain-reputation blocklists. AI tooling is now a force multiplier: Chainalysis found AI-augmented scam operations generated 4.5x more revenue per operation ($3.2M vs $719K) than non-AI operations, and impersonation-scam severity/volume surged over 1400% and 600% respectively year over year, driven partly by AI-generated, constantly-rotating phishing content that defeats static detection.

At scale, Chainalysis attributes at least $14 billion in confirmed on-chain crypto scam revenue in 2025 (projected to exceed $17 billion as more addresses are attributed), with the average payment per scam address up 253% YoY ($782 to $2,764), and total approval-phishing losses since May 2021 estimated at $2.7 billion. Once drained, proceeds move through a documented laundering pipeline — reused consolidation wallets and spender contracts, cross-chain bridging, and Chinese-language laundering marketplaces such as Huione Guarantee — before cashing out at exchanges.

In response, Chainalysis and law-enforcement partners have run an escalating series of named disruption operations. Operation Disruption (a March 2024 pilot with Calgary Police Service) became Operation Spincaster (launched July 2024): an ecosystem-wide initiative spanning six countries (US, UK, Canada, Spain, Netherlands, Australia), 12 public-sector agencies, and 17 exchanges (including Binance and NDAX), generating 7,000+ investigative leads tied to roughly $162 million in losses and a new real-time exchange-screening API. Operation DeCloak (Delta, British Columbia, Canada, September 2024) examined 240 addresses tied to over $25 million in estimated losses, identified 1,100+ victims, traced $1.2 million to a blacklisted address under overseas seizure and $800,000 across 70 additional transactions, and disseminated nearly 100 leads. A prior effort, Project Atlas (2024), identified over 2,000 compromised wallets, disrupted roughly $70 million in potential fraud, and froze about $24 million. Most recently, Operation Atlantic (announced March 16, 2026, by the US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission, with Chainalysis support) identified more than 20,000 victims across the UK, Canada, and US, froze $12 million in suspected criminal proceeds, and traced an additional $45 million in related stolen cryptocurrency.

MITRE ATT&CK techniques used in TL-2026-1708

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion

Command and Control

T1102 Web Service; T1573 Encrypted Channel

Execution

T1204 User Execution

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Reconnaissance

T1593 Search Open Websites/Domains

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Approval Phishing

  • Ethereum Virtual Machine (EVM) Ecosystem — ERC-20 approve() / transferFrom() token-approval mechanism
    Vulnerable versions: All EVM-compatible chains implementing the ERC-20 standard
    Fixed in: N/A - abuse of intended wallet-permission functionality via social engineering, not a software defect
  • EIP-2612 — permit() off-chain gasless token-approval signature standard
    Vulnerable versions: All EIP-2612-compliant tokens and contracts
    Fixed in: N/A
  • Ethereum (post-Pectra upgrade) — EIP-7702 SET_CODE (0x04) account-delegation transaction type
    Vulnerable versions: Ethereum mainnet and EVM chains supporting EIP-7702 account delegation
    Fixed in: N/A
  • Multi-chain (Inferno Drainer Reloaded targeting) — Ethereum, BNB Smart Chain, Polygon, Base
    Vulnerable versions: N/A - chain-agnostic social-engineering campaign using cross-chain drainer templates
    Fixed in: N/A

Remediation for Approval Phishing

Immediate actions

  • Revoke unlimited or unfamiliar token/NFT approvals immediately via a revocation tool (e.g., a block-explorer token-approval checker) upon any suspicion of compromise
  • Contact affected exchanges and investigators immediately to flag destination/consolidation addresses and attempt to freeze in-transit funds before they are layered across services, mirroring the Operation Spincaster/Atlantic real-time triage model
  • Directly warn identified at-risk victims to revoke a pending or already-granted approval before the scammer executes the drain

Workarounds

  • Prefer time-limited or capped token allowances over unlimited approve() grants where wallet/dApp tooling supports it
  • Treat unsolicited 'wallet upgrade,' 'security enhancement,' or 'AI assistant authorization' prompts that request EIP-7702 delegation as high risk and refuse without independent, out-of-band verification
  • Refuse instructions from an unsolicited 'mentor,' support contact, or investment coach to move funds off a regulated exchange into self-custody

Longer-term hardening

  • Wire the approval-phishing typology into transaction-monitoring and compliance systems, flagging cases where the address spending funds is not the address that owns them
  • Adopt or require wallet software with pre-signature transaction simulation and human-readable permission decoding that flags open-ended or unlimited approvals and EIP-7702 delegation requests
  • Cross-reference outbound transactions against known drain-destination wallets, spender contracts, and exchange deposit addresses that recur across multiple victims
  • Participate in cross-border and cross-sector information sharing (e.g., US Bank Secrecy Act 314(b) channels, multi-exchange investigative sprints modeled on Operation Spincaster) to disseminate leads in near real time

Timeline of Approval Phishing

  • Chainalysis begins the loss-tracking window later cited as the baseline for approval phishing: cumulative losses reach an estimated $2.7 billion by the time Operation Spincaster is disclosed in 2024.
  • Operation Disruption pilot runs with Calgary Police Service, the precursor effort that is scaled into Operation Spincaster.
  • Chainalysis launches Operation Spincaster, an ecosystem-wide initiative across six countries (US, UK, Canada, Spain, Netherlands, Australia), 12 public-sector agencies, and 17 exchanges including Binance and NDAX, generating 7,000+ leads tied to roughly $162 million in losses.
  • Operation DeCloak runs in Delta, British Columbia, Canada with seven agencies (Delta Police, RCMP, Victoria Police, BCSC, BCFSA, BC Prosecution Service, Vancouver Police) and exchange Shakepay: 240 addresses examined (~$25M+ in estimated losses), 1,100+ victims identified, $1.2M traced to a blacklisted address under overseas seizure, $800K across 70 additional transactions, and nearly 100 leads disseminated.
  • Project Atlas (2024) is later cited as identifying over 2,000 compromised wallets, disrupting roughly $70 million in potential fraud, and freezing about $24 million in stolen crypto.
  • Inferno Drainer Reloaded campaign begins, ultimately stealing over $9 million from 30,000+ wallets across Ethereum, BNB Smart Chain, Polygon, and Base through May 2025 using on-chain encrypted C2 and self-destructing contracts.
  • Inferno Drainer Reloaded's documented March-May 2025 theft window closes, having drained 30,000+ wallets.
  • Full-year 2025 figures close out at an estimated $14 billion confirmed on-chain crypto scam revenue (projected to exceed $17 billion as more addresses are attributed), average scam payment up 253% YoY ($782 to $2,764), and impersonation-scam severity up over 600% / volume up over 1400% YoY.
  • Chainalysis publishes its 2026 Crypto Crime Report scams chapter, disclosing the $14-17B scam-revenue figures and naming impersonation/AI-augmented scams as surpassing hacks/cyberattacks as crypto's biggest threat category.
  • The US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission jointly announce Operation Atlantic, a coordinated real-time disruption effort against approval-phishing scams.
  • Chainalysis publishes Operation Atlantic results: 20,000+ victims identified across the UK, Canada, and US, $12 million in suspected criminal proceeds frozen, and $45 million in related stolen cryptocurrency traced; one UK victim alone lost over £52,000.

Sources cited for Approval Phishing

Detection coverage for TL-2026-1708

As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1708 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats