# Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak, and Atlantic

> Chainalysis details "approval phishing," a cryptocurrency scam typology in which victims are socially engineered into granting malicious actors wallet-approval access, allowing scammers to drain funds via transactions that appear minor but contain hidden implications. The report covers law-enforcement and private-sector disruption operations (Spincaster, DeCloak, Atlantic) that froze and traced tens of millions of dollars in proceeds amid a broader on-chain scam ecosystem generating an estimated $14-17 billion in 2025.

- **Published:** 2026-07-26T00:00:00Z
- **Last reviewed:** 2026-07-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1708
- **ID:** TL-2026-1708
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Approval phishing abuses standard, intended EVM wallet-permission functionality rather than a software vulnerability. Victims are socially engineered — often by a coached 'mentor' or support persona who directs them off regulated exchanges into self-custody using urgency and rehearsed investment narratives — into signing a transaction that looks minor but actually grants a scammer's address broad spending authority over their wallet. The three technical vectors documented across sourced research are: (1) the ERC-20 approve()/transferFrom() pattern, where a victim grants an unlimited allowance and the scammer later calls transferFrom() to drain tokens; (2) EIP-2612 permit() off-chain gasless-approval signatures, which leave no on-chain trace until the scammer executes the transfer, evading standard approval monitoring; and (3) the newer EIP-7702 SET_CODE (0x04) account-delegation transaction type, where victims are told they are performing a 'wallet upgrade,' 'security enhancement,' or 'AI assistant authorization' but are actually delegating execution authority to a malicious contract that can move funds without further prompts. NFT holders face an analogous setApprovalForAll abuse pattern.

The attack is increasingly commoditized: drainer-as-a-service kits (Inferno Drainer, Inferno Drainer Reloaded, Angel Drainer, Pink Drainer) and phishing-as-a-service platforms (Lighthouse) let low-skill affiliates deploy cloned dApp phishing pages for a cut (historically ~20-30%) of stolen proceeds. Inferno Drainer Reloaded (March-May 2025) stole over $9 million from 30,000+ wallets across Ethereum, BNB Smart Chain, Polygon, and Base using on-chain encrypted command-and-control, self-destructing contracts to dodge blacklists, and 'Red Pill' logic that behaves benignly during wallet-simulation checks (e.g., Rabby, MetaMask) and only executes the malicious drain after the victim signs -- exploiting the time-of-check/time-of-use (TOCTOU) gap between wallet-simulation state and live on-chain execution state, per ThreeSigma technical analysis; the same source documents phishing kits bundling obfuscated JavaScript that auto-generates and auto-fills EIP-7702 delegation payloads with a single pasted script line, and campaign infrastructure hosted on free platforms (GitHub Pages, Webflow) as well as compromised legitimate websites to inherit trust and evade domain-reputation blocklists. AI tooling is now a force multiplier: Chainalysis found AI-augmented scam operations generated 4.5x more revenue per operation ($3.2M vs $719K) than non-AI operations, and impersonation-scam severity/volume surged over 1400% and 600% respectively year over year, driven partly by AI-generated, constantly-rotating phishing content that defeats static detection.

At scale, Chainalysis attributes at least $14 billion in confirmed on-chain crypto scam revenue in 2025 (projected to exceed $17 billion as more addresses are attributed), with the average payment per scam address up 253% YoY ($782 to $2,764), and total approval-phishing losses since May 2021 estimated at $2.7 billion. Once drained, proceeds move through a documented laundering pipeline — reused consolidation wallets and spender contracts, cross-chain bridging, and Chinese-language laundering marketplaces such as Huione Guarantee — before cashing out at exchanges.

In response, Chainalysis and law-enforcement partners have run an escalating series of named disruption operations. Operation Disruption (a March 2024 pilot with Calgary Police Service) became Operation Spincaster (launched July 2024): an ecosystem-wide initiative spanning six countries (US, UK, Canada, Spain, Netherlands, Australia), 12 public-sector agencies, and 17 exchanges (including Binance and NDAX), generating 7,000+ investigative leads tied to roughly $162 million in losses and a new real-time exchange-screening API. Operation DeCloak (Delta, British Columbia, Canada, September 2024) examined 240 addresses tied to over $25 million in estimated losses, identified 1,100+ victims, traced $1.2 million to a blacklisted address under overseas seizure and $800,000 across 70 additional transactions, and disseminated nearly 100 leads. A prior effort, Project Atlas (2024), identified over 2,000 compromised wallets, disrupted roughly $70 million in potential fraud, and froze about $24 million. Most recently, Operation Atlantic (announced March 16, 2026, by the US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission, with Chainalysis support) identified more than 20,000 victims across the UK, Canada, and US, froze $12 million in suspected criminal proceeds, and traced an additional $45 million in related stolen cryptocurrency.

## MITRE ATT&CK

- T1593 Search Open Websites/Domains
- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1036 Masquerading
- T1684.001 Impersonation
- T1070 Indicator Removal
- T1497 Virtualization/Sandbox Evasion
- T1027 Obfuscated Files or Information
- T1102 Web Service
- T1573 Encrypted Channel
- T1657 Financial Theft

## Sources

- [Approval Phishing: From Just One Case to Full-Scale Disruption](https://www.chainalysis.com/blog/approval-phishing-from-just-one-case-to-full-scale-disruption/)
- [What Is Approval Phishing? Detect & Disrupt Crypto Scams at Scale](https://www.chainalysis.com/blog/what-is-approval-phishing/)
- [How Public-Private Collaboration Is Freezing Crypto Scam Proceeds (Operation Atlantic)](https://www.chainalysis.com/blog/operation-atlantic-freezing-crypto-scam-proceeds/)
- [Operation Spincaster: Disrupt & Prevent Losses in Crypto Scams](https://www.chainalysis.com/blog/operation-spincaster/)
- [Local Police in Delta, CA Equipped to Trace, Freeze Millions from Scam Wallet (Operation DeCloak)](https://www.chainalysis.com/blog/operation-spincaster-lands-in-delta-local-police-equipped-to-trace-and-freeze-millions-from-scam-wallet/)
- [2026 Crypto Crime Report: Scams](https://www.chainalysis.com/blog/crypto-scams-2026/)
- [International police launch Operation Atlantic to combat crypto approval phishing scams](https://www.coindesk.com/business/2026/03/16/u-s-uk-canada-start-operation-atlantic-to-disrupt-crypto-approval-phishing-scams)
- [Inside Wallet Drainers and EIP-7702 Exploits](https://threesigma.xyz/blog/opsec/ai-phishing-wallet-drainers-eip7702-part-2)
- [The Rising Threat of Phishing Attacks with Crypto Drainers](https://research.checkpoint.com/2023/the-rising-threat-of-phishing-attacks-with-crypto-drainers/)
- [Cryptocurrency wallet drainers stole $494 million in 2024](https://www.bleepingcomputer.com/news/security/cryptocurrency-wallet-drainers-stole-494-million-in-2024/)
- [Approval phishing scams: what they mean for fraud and identity teams](https://nhimg.org/community/identity-beyond-iam/approval-phishing-scams-what-they-mean-for-fraud-and-identity-teams/)
- [Crypto scam losses could reach $17B as approval phishing operations scale, says Chainalysis](https://ambcrypto.com/crypto-scam-losses-could-reach-17b-as-approval-phishing-operations-scale-says-chainalysis/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1708
