Operation Atlantic, a week-long international law enforcement campaign launched on March 16, 2026, froze $12 million in suspected criminal proceeds and identified more than $45 million in cryptocurrency linked to approval phishing fraud across 30+ countries. The operation, co-hosted by the UK Nat...
"Approval phishing is one of the most damaging types of scams targeting crypto users today." — Flavio Tonon, Senior Regional Advisor EMEA, Binance
Operation Atlantic, a week-long international law enforcement campaign launched on March 16, 2026, froze $12 million in suspected criminal proceeds and identified more than $45 million in cryptocurrency linked to approval phishing fraud across 30+ countries. The operation, co-hosted by the UK National Crime Agency, US Secret Service, Ontario Provincial Police, and Ontario Securities Commission, flagged 20,000+ victim wallet addresses and disrupted over 120 scam domains.
The action arrives at a critical inflection point. The FBI's 2025 Internet Crime Report recorded $11.4 billion in crypto-related fraud losses in the United States alone — a 22% year-over-year increase — while Chainalysis estimated $17 billion globally. Approval phishing, the specific vector targeted by Operation Atlantic, exploits the ERC-20 token approval mechanism to drain wallets long after a victim signs a single malicious transaction.
This report examines the operation's scope, the technical mechanics of approval phishing, the scale of the broader threat, and what the public-private enforcement model implies for crypto security infrastructure.
Operation Atlantic ran for one week beginning March 16, 2026, headquartered at the NCA's London offices. According to the US Secret Service, the operation disrupted more than $45 million in cryptocurrency fraud schemes worldwide and froze $12 million in stolen funds earmarked for victim restitution.
By the numbers:
| Metric | Value | |--------|-------| | Stolen funds frozen | $12 million | | Total fraud identified | $45 million+ | | Victim wallets flagged | 20,000+ | | Countries with victims | 30+ | | Scam domains disrupted | 120+ | | Single largest phishing network | $15 million in victim losses |
The NCA led coordination across six agencies: the US Secret Service, Ontario Provincial Police, Ontario Securities Commission, City of London Police, and the Financial Conduct Authority. Private-sector partners included Coinbase, Binance, TRM Labs, and Chainalysis.
One individual UK victim lost £52,000. TRM Labs noted that one approval phishing network alone accounted for $15 million in victim losses. According to TRM, fraudsters now move stolen funds within 48 hours of theft, compressing the intervention window available to law enforcement.
NCA Deputy Director of Investigations Miles Bonfield stated: "Operation Atlantic is a powerful example of what is possible when international agencies and private industry work side by side."
Approval phishing exploits a fundamental design pattern in ERC-20 tokens: the approve() function. This function allows a wallet holder to grant a third-party smart contract permission to spend tokens on their behalf — a necessary mechanism for decentralized exchanges, lending protocols, and other DeFi applications.
The attack proceeds in stages:
Stage 1 — Social Engineering. Victims are lured to phishing websites that clone legitimate platforms — Uniswap, OpenSea, or bespoke "investment portals." Romance fraud and pig-butchering schemes are common onramps, sometimes involving weeks of grooming before the victim is directed to a malicious site.
Stage 2 — The Malicious Approval. The victim connects their wallet and signs a transaction. The transaction appears routine but grants unlimited token approval to an attacker-controlled address. Most wallet interfaces do not clearly distinguish between limited and unlimited approval requests.
Stage 3 — The Drain. The attacker calls transferFrom() on the approved tokens, moving funds to consolidation wallets. This can occur days, weeks, or months after the initial approval. No additional signature from the victim is required.
A more sophisticated variant leverages EIP-2612's permit() function, which enables off-chain signing. The victim signs a gasless message — no on-chain transaction is created — and the attacker later relays the signed permit to drain tokens. Because no gas fee is incurred at signing time, the victim may not recognize the interaction as consequential.
Following Ethereum's Pectra upgrade in May 2025, Scam Sniffer documented attackers exploiting EIP-7702-based signatures, which bundle multiple harmful actions into a single approval. Two major EIP-7702 cases in August 2025 resulted in $2.54 million in losses.
The critical distinction from traditional credential phishing: approval phishing does not steal passwords or private keys. It exploits a legitimate on-chain permission system. The approval remains valid indefinitely unless explicitly revoked, and legacy approvals granted years earlier can be activated at any time.
Multiple data sources converge on a picture of persistent, large-scale damage from crypto fraud, with approval phishing as a significant and evolving vector.
FBI IC3 2025 Report (US only):
Chainalysis 2026 Crypto Crime Report (global):
Scam Sniffer 2025 Annual Report (wallet drainer/phishing specific):
The Scam Sniffer data presents a seeming contradiction: wallet drainer losses fell 83% while FBI-reported crypto fraud losses rose 22%. The explanation lies in scope. Scam Sniffer tracks on-chain wallet drainer kits — a specific technical vector. The FBI captures all crypto-related fraud complaints including pig-butchering, romance scams, and investment fraud where approval phishing is one mechanism among many. TRM Labs' $35 billion figure encompasses the broadest definition, including all fraud-adjacent flows.
The FBI's Operation Level Up, a parallel initiative, notified 3,780 victims of crypto investment fraud in 2025. According to the FBI, 78% were unaware they were being scammed at the time of notification.
Early 2026 indicators suggest the threat continues. Signature phishing losses jumped 207% in January 2026 compared to December 2025, according to Scam Sniffer. Impersonation tactics showed 1,400% year-over-year growth, per Chainalysis.
Operation Atlantic's most notable feature is its operational structure: law enforcement agencies embedded private-sector blockchain analytics firms directly into the investigation.
Binance deployed its Special Investigations team to NCA headquarters in London. The team conducted real-time account screening, victim identification, and scam website research. According to the company, no funds were seized from Binance accounts — criminal proceeds had already moved off-platform. In 2025, Binance supported over 71,000 law enforcement requests and assisted in confiscating more than $131 million in illicit funds.
TRM Labs prepared pre-built investigative workflows for approval phishing cases, conducted blockchain tracing during the sprint, and produced what it described as "seizure-ready intelligence packages" linked to major networks. TRM leveraged its blockchain analytics platform and Chainabuse.com intelligence database.
Chainalysis provided blockchain analysis and intelligence support for tracking illicit fund flows across distributed ledgers.
Coinbase partnered on victim identification and outreach across its user base.
This model — law enforcement providing legal authority and coordination, private firms providing technical infrastructure and real-time analytics — represents a maturing approach to crypto-native crime. The 48-hour fund-movement window cited by TRM Labs makes traditional investigative timelines inadequate. Blockchain tracing tools compress the identification-to-freeze cycle from weeks to hours.
The question is whether a week-long sprint that freezes $12 million materially deters fraud operations generating $17 billion annually. The ratio — roughly $1 frozen for every $1,400 stolen — suggests enforcement capacity remains orders of magnitude below the threat. Operation Atlantic's value may lie less in its direct financial recovery and more in its demonstration that approval phishing networks can be mapped and disrupted at scale.
The approval phishing threat has generated a parallel ecosystem of defensive tooling.
Revocation tools. Revoke.cash, Etherscan's Token Approval Checker, and MetaMask Portfolio allow users to audit and revoke outstanding token approvals. Adoption data is sparse, but the tools exist.
Wallet-level protections. Trust Wallet's Security Scanner and Blockaid's transaction simulation engine attempt to flag malicious approvals before signing. These operate as middleware between the user and the transaction.
Protocol-level mitigations. Some protocols have moved toward time-limited approvals or approval caps. However, the ERC-20 standard's default approve() function accepts type(uint256).max as a parameter — effectively infinite approval — and this remains the norm for gas efficiency.
User behavior. The FBI's finding that 78% of victims in Operation Level Up were unaware they were being scammed underscores a fundamental challenge. Technical mitigations are only effective if users deploy them. The social engineering layer — romance scams, fake investment portals, impersonation — bypasses technical literacy.
approve() function design enables the attack vector at the protocol level. Defensive tooling exists but depends on user adoption.Operation Atlantic demonstrates that international law enforcement can identify and freeze approval phishing proceeds at scale when partnered with blockchain analytics firms. The $12 million frozen and 20,000 victims identified in a single week represent a logistical achievement in cross-border coordination.
The structural problem remains. The token approval mechanism that enables DeFi composability is the same mechanism that enables approval phishing. Freezing $12 million in a $17-billion-per-year fraud environment is a proof of concept, not a solution. The 48-hour fund-movement window identified by TRM Labs means continuous monitoring infrastructure — not periodic enforcement sprints — is what the threat requires.
The data suggests the crypto industry's security challenge is shifting from smart contract exploits toward social engineering at the wallet-permission layer. Protocol-level fixes (time-limited approvals, better wallet UX for approval requests) and sustained public-private monitoring infrastructure would address the vector more directly than periodic enforcement actions. Whether the industry funds that infrastructure, or waits for regulators to mandate it, is an open question.