Threat reportPhishingTL-2026-1708
Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak, and Atlantic
Approval Phishing (TL-2026-1708), also tracked as Wallet-Drainer Scam, is a high-severity phishing campaign, first published 2026-07-26. It has no confirmed attribution, affects Ethereum Virtual Machine (EVM) Ecosystem ERC-20 approve() /, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1070), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1708
- Threat ID
- TL-2026-1708
- Also known as
- Wallet-Drainer Scam, Token-Approval Scam, Permit Phishing, Wallet-Approval Scam
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- individual cryptocurrency holders, self-custody wallet users, cryptocurrency exchanges, retail investors, financial services
- Target regions
- united states of america, united kingdom, canada, spain, netherlands, australia, Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Approval Phishing
Malware and tooling: Angel Drainer, Chainalysis Reactor / Chainalysis Data Solutions, Inferno Drainer, Inferno Drainer Reloaded, On-chain encrypted command-and-control channel, Pink Drainer
How Approval Phishing works
Chainalysis details "approval phishing," a cryptocurrency scam typology in which victims are socially engineered into granting malicious actors wallet-approval access, allowing scammers to drain funds via transactions that appear minor but contain hidden implications. The report covers law-enforcement and private-sector disruption operations (Spincaster, DeCloak, Atlantic) that froze and traced tens of millions of dollars in proceeds amid a broader on-chain scam ecosystem generating an estimated $14-17 billion in 2025.
Approval phishing abuses standard, intended EVM wallet-permission functionality rather than a software vulnerability. Victims are socially engineered — often by a coached 'mentor' or support persona who directs them off regulated exchanges into self-custody using urgency and rehearsed investment narratives — into signing a transaction that looks minor but actually grants a scammer's address broad spending authority over their wallet. The three technical vectors documented across sourced research are: (1) the ERC-20 approve()/transferFrom() pattern, where a victim grants an unlimited allowance and the scammer later calls transferFrom() to drain tokens; (2) EIP-2612 permit() off-chain gasless-approval signatures, which leave no on-chain trace until the scammer executes the transfer, evading standard approval monitoring; and (3) the newer EIP-7702 SET_CODE (0x04) account-delegation transaction type, where victims are told they are performing a 'wallet upgrade,' 'security enhancement,' or 'AI assistant authorization' but are actually delegating execution authority to a malicious contract that can move funds without further prompts. NFT holders face an analogous setApprovalForAll abuse pattern.
The attack is increasingly commoditized: drainer-as-a-service kits (Inferno Drainer, Inferno Drainer Reloaded, Angel Drainer, Pink Drainer) and phishing-as-a-service platforms (Lighthouse) let low-skill affiliates deploy cloned dApp phishing pages for a cut (historically ~20-30%) of stolen proceeds. Inferno Drainer Reloaded (March-May 2025) stole over $9 million from 30,000+ wallets across Ethereum, BNB Smart Chain, Polygon, and Base using on-chain encrypted command-and-control, self-destructing contracts to dodge blacklists, and 'Red Pill' logic that behaves benignly during wallet-simulation checks (e.g., Rabby, MetaMask) and only executes the malicious drain after the victim signs -- exploiting the time-of-check/time-of-use (TOCTOU) gap between wallet-simulation state and live on-chain execution state, per ThreeSigma technical analysis; the same source documents phishing kits bundling obfuscated JavaScript that auto-generates and auto-fills EIP-7702 delegation payloads with a single pasted script line, and campaign infrastructure hosted on free platforms (GitHub Pages, Webflow) as well as compromised legitimate websites to inherit trust and evade domain-reputation blocklists. AI tooling is now a force multiplier: Chainalysis found AI-augmented scam operations generated 4.5x more revenue per operation ($3.2M vs $719K) than non-AI operations, and impersonation-scam severity/volume surged over 1400% and 600% respectively year over year, driven partly by AI-generated, constantly-rotating phishing content that defeats static detection.
At scale, Chainalysis attributes at least $14 billion in confirmed on-chain crypto scam revenue in 2025 (projected to exceed $17 billion as more addresses are attributed), with the average payment per scam address up 253% YoY ($782 to $2,764), and total approval-phishing losses since May 2021 estimated at $2.7 billion. Once drained, proceeds move through a documented laundering pipeline — reused consolidation wallets and spender contracts, cross-chain bridging, and Chinese-language laundering marketplaces such as Huione Guarantee — before cashing out at exchanges.
In response, Chainalysis and law-enforcement partners have run an escalating series of named disruption operations. Operation Disruption (a March 2024 pilot with Calgary Police Service) became Operation Spincaster (launched July 2024): an ecosystem-wide initiative spanning six countries (US, UK, Canada, Spain, Netherlands, Australia), 12 public-sector agencies, and 17 exchanges (including Binance and NDAX), generating 7,000+ investigative leads tied to roughly $162 million in losses and a new real-time exchange-screening API. Operation DeCloak (Delta, British Columbia, Canada, September 2024) examined 240 addresses tied to over $25 million in estimated losses, identified 1,100+ victims, traced $1.2 million to a blacklisted address under overseas seizure and $800,000 across 70 additional transactions, and disseminated nearly 100 leads. A prior effort, Project Atlas (2024), identified over 2,000 compromised wallets, disrupted roughly $70 million in potential fraud, and froze about $24 million. Most recently, Operation Atlantic (announced March 16, 2026, by the US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission, with Chainalysis support) identified more than 20,000 victims across the UK, Canada, and US, froze $12 million in suspected criminal proceeds, and traced an additional $45 million in related stolen cryptocurrency.
MITRE ATT&CK techniques used in TL-2026-1708
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion
Command and Control
T1102 Web Service; T1573 Encrypted Channel
Execution
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Reconnaissance
T1593 Search Open Websites/Domains
Impact
stealth
Affected products and versions in Approval Phishing
- Ethereum Virtual Machine (EVM) Ecosystem — ERC-20 approve() / transferFrom() token-approval mechanism
Vulnerable versions: All EVM-compatible chains implementing the ERC-20 standard
Fixed in: N/A - abuse of intended wallet-permission functionality via social engineering, not a software defect - EIP-2612 — permit() off-chain gasless token-approval signature standard
Vulnerable versions: All EIP-2612-compliant tokens and contracts
Fixed in: N/A - Ethereum (post-Pectra upgrade) — EIP-7702 SET_CODE (0x04) account-delegation transaction type
Vulnerable versions: Ethereum mainnet and EVM chains supporting EIP-7702 account delegation
Fixed in: N/A - Multi-chain (Inferno Drainer Reloaded targeting) — Ethereum, BNB Smart Chain, Polygon, Base
Vulnerable versions: N/A - chain-agnostic social-engineering campaign using cross-chain drainer templates
Fixed in: N/A
Remediation for Approval Phishing
Immediate actions
- Revoke unlimited or unfamiliar token/NFT approvals immediately via a revocation tool (e.g., a block-explorer token-approval checker) upon any suspicion of compromise
- Contact affected exchanges and investigators immediately to flag destination/consolidation addresses and attempt to freeze in-transit funds before they are layered across services, mirroring the Operation Spincaster/Atlantic real-time triage model
- Directly warn identified at-risk victims to revoke a pending or already-granted approval before the scammer executes the drain
Workarounds
- Prefer time-limited or capped token allowances over unlimited approve() grants where wallet/dApp tooling supports it
- Treat unsolicited 'wallet upgrade,' 'security enhancement,' or 'AI assistant authorization' prompts that request EIP-7702 delegation as high risk and refuse without independent, out-of-band verification
- Refuse instructions from an unsolicited 'mentor,' support contact, or investment coach to move funds off a regulated exchange into self-custody
Longer-term hardening
- Wire the approval-phishing typology into transaction-monitoring and compliance systems, flagging cases where the address spending funds is not the address that owns them
- Adopt or require wallet software with pre-signature transaction simulation and human-readable permission decoding that flags open-ended or unlimited approvals and EIP-7702 delegation requests
- Cross-reference outbound transactions against known drain-destination wallets, spender contracts, and exchange deposit addresses that recur across multiple victims
- Participate in cross-border and cross-sector information sharing (e.g., US Bank Secrecy Act 314(b) channels, multi-exchange investigative sprints modeled on Operation Spincaster) to disseminate leads in near real time
Timeline of Approval Phishing
- Chainalysis begins the loss-tracking window later cited as the baseline for approval phishing: cumulative losses reach an estimated $2.7 billion by the time Operation Spincaster is disclosed in 2024.
- Operation Disruption pilot runs with Calgary Police Service, the precursor effort that is scaled into Operation Spincaster.
- Chainalysis launches Operation Spincaster, an ecosystem-wide initiative across six countries (US, UK, Canada, Spain, Netherlands, Australia), 12 public-sector agencies, and 17 exchanges including Binance and NDAX, generating 7,000+ leads tied to roughly $162 million in losses.
- Operation DeCloak runs in Delta, British Columbia, Canada with seven agencies (Delta Police, RCMP, Victoria Police, BCSC, BCFSA, BC Prosecution Service, Vancouver Police) and exchange Shakepay: 240 addresses examined (~$25M+ in estimated losses), 1,100+ victims identified, $1.2M traced to a blacklisted address under overseas seizure, $800K across 70 additional transactions, and nearly 100 leads disseminated.
- Project Atlas (2024) is later cited as identifying over 2,000 compromised wallets, disrupting roughly $70 million in potential fraud, and freezing about $24 million in stolen crypto.
- Inferno Drainer Reloaded campaign begins, ultimately stealing over $9 million from 30,000+ wallets across Ethereum, BNB Smart Chain, Polygon, and Base through May 2025 using on-chain encrypted C2 and self-destructing contracts.
- Inferno Drainer Reloaded's documented March-May 2025 theft window closes, having drained 30,000+ wallets.
- Full-year 2025 figures close out at an estimated $14 billion confirmed on-chain crypto scam revenue (projected to exceed $17 billion as more addresses are attributed), average scam payment up 253% YoY ($782 to $2,764), and impersonation-scam severity up over 600% / volume up over 1400% YoY.
- Chainalysis publishes its 2026 Crypto Crime Report scams chapter, disclosing the $14-17B scam-revenue figures and naming impersonation/AI-augmented scams as surpassing hacks/cyberattacks as crypto's biggest threat category.
- The US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission jointly announce Operation Atlantic, a coordinated real-time disruption effort against approval-phishing scams.
- Chainalysis publishes Operation Atlantic results: 20,000+ victims identified across the UK, Canada, and US, $12 million in suspected criminal proceeds frozen, and $45 million in related stolen cryptocurrency traced; one UK victim alone lost over £52,000.
Sources cited for Approval Phishing
- Approval Phishing: From Just One Case to Full-Scale Disruption
- What Is Approval Phishing? Detect & Disrupt Crypto Scams at Scale
- How Public-Private Collaboration Is Freezing Crypto Scam Proceeds (Operation Atlantic)
- Operation Spincaster: Disrupt & Prevent Losses in Crypto Scams
- Local Police in Delta, CA Equipped to Trace, Freeze Millions from Scam Wallet (Operation DeCloak)
- 2026 Crypto Crime Report: Scams
- International police launch Operation Atlantic to combat crypto approval phishing scams
- Inside Wallet Drainers and EIP-7702 Exploits
- The Rising Threat of Phishing Attacks with Crypto Drainers
- Cryptocurrency wallet drainers stole $494 million in 2024
- Approval phishing scams: what they mean for fraud and identity teams
- Crypto scam losses could reach $17B as approval phishing operations scale, says Chainalysis
Detection coverage for TL-2026-1708
As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1708 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.