April 15, 2026

Operation Atlantic: How Approval Phishing Targeted 20,000 Crypto Wallets

Operation Atlantic: How Approval Phishing Targeted 20,000 Crypto Wallets

An international operation led by the UK National Crime Agency has highlighted a form of cryptocurrency fraud that can allow criminals to remove assets from a victim’s wallet without directly obtaining the private key.

Operation Atlantic focused on approval phishing, a technique in which victims are deceived into granting a malicious party permission to access or transfer particular cryptoassets.

The operation identified more than 20,000 people across the UK, Canada and the United States who had lost cryptocurrency or were at risk of losing it. More than $12 million in suspected criminal proceeds was secured and frozen, while investigators identified more than $45 million stolen through cryptocurrency fraud schemes worldwide. One UK victim was believed to have lost more than £52,000.

These figures describe different outcomes. Identifying stolen assets, freezing suspected proceeds and returning money to victims are separate stages.

What Was Operation Atlantic?

Operation Atlantic was coordinated by the National Crime Agency alongside the United States Secret Service, Ontario Provincial Police and Ontario Securities Commission.

UK and international law-enforcement bodies worked with cryptocurrency businesses and other private-sector organisations to share intelligence, analyse blockchain activity and contact people who appeared to have been affected by fraud.

The operation focused on individuals who had already lost cryptoassets or whose wallets remained at risk because they had granted malicious token permissions.

The NCA reported that real-time analysis and victim outreach allowed some funds to be secured before criminals could move them. Intelligence gathered during the operation was also retained to support affected victims and further investigations.

Operation Atlantic demonstrates how cooperation between investigators, wallet providers, exchanges, blockchain-analysis companies and law-enforcement agencies may help identify suspicious activity.

It does not mean every identified victim will recover their losses or that every associated wallet controller has been identified.

What Is Approval Phishing?

Approval phishing occurs when a victim is deceived into authorising a smart contract or wallet address to transfer certain tokens from their cryptocurrency wallet.

Many blockchain-based services require users to approve token access before completing activities such as:

  • Swapping one cryptocurrency for another
  • Buying an asset through a decentralised application
  • Connecting to an investment platform
  • Providing liquidity
  • Staking tokens
  • Interacting with a blockchain game or marketplace

A legitimate approval allows the chosen service to transfer a specified token for an intended purpose.

A malicious approval may give a fraudster permission to transfer some or all of the victim’s tokens. The criminal may exploit that permission immediately or wait until more valuable assets enter the wallet.

The victim may believe they are:

  • Connecting to a genuine investment platform
  • Verifying their wallet
  • Claiming an airdrop
  • Authorising a routine transaction
  • Recovering a failed payment
  • Unlocking investment profits
  • Completing a security check

The request may appear through a fake website, fraudulent application, pop-up, email or link sent by someone posing as a trusted adviser or investment representative.

Once the approval is granted, the criminal may be able to transfer the relevant assets without asking the victim to approve each later transaction.

How Is Approval Phishing Different from a Fake Investment Platform?

Approval phishing often appears within wider investment fraud, including scams sometimes described as pig butchering.

However, the mechanism is different from simply persuading a victim to send cryptocurrency to a fraudster’s wallet.

In a conventional fake-investment scheme, the victim may repeatedly transfer funds to wallet addresses provided by the supposed platform. The displayed account balance and profits are usually fabricated.

In approval phishing, the victim may continue to hold assets in their own wallet while unknowingly granting a malicious party permission to move them.

The fraud may therefore involve:

  • A false investment website
  • A supposedly profitable trading account
  • Instructions to connect a personal wallet
  • A fraudulent approval request
  • Later unauthorised transfers from the wallet

The distinction is important when reviewing the evidence. Investigators may need to examine both the payments made by the victim and the approval transactions recorded on the blockchain.

How Were More Than 20,000 Victims Identified?

Public blockchains record transactions and smart-contract interactions.

Where analysts identify a wallet, contract or approval mechanism connected to fraudulent activity, they may be able to review other addresses that interacted with it.

This can help identify wallets that:

  • Granted the same malicious permission
  • Sent assets to associated addresses
  • Received or transferred related tokens
  • Interacted with a known fraudulent contract
  • Remained exposed to further unauthorised transfers

A wallet address does not normally reveal the name of the person controlling it.

Connecting a wallet to an individual may require information held by a cryptocurrency exchange, wallet provider, bank or other service. It may also depend on previous reports, communications or formal legal and law-enforcement enquiries.

The 20,000 figure therefore refers to people identified through the wider operation, including those who had lost cryptocurrency and those assessed as being at risk. It should not be interpreted as confirmation that every identified wallet suffered a completed loss.

What Do the $12 Million and $45 Million Figures Mean?

The official figures should not be combined or described as recovered funds.

The NCA reported that:

  • More than $12 million in suspected criminal proceeds was secured and frozen
  • More than $45 million stolen through cryptocurrency fraud schemes was identified worldwide

Freezing restricts access to suspected assets. Identification means investigators have linked transactions or assets to suspected fraudulent activity.

Neither outcome necessarily means the money has been returned to victims.

Further steps may be required to establish:

  • Who legally controls the relevant wallets or accounts
  • Which transactions relate to particular victims
  • Whether the assets remain available
  • Which jurisdiction applies
  • Whether a court or authority can make the necessary orders
  • Whether other victims or parties have competing claims
  • How any restrained assets should be distributed

An announcement that assets have been frozen should therefore not be treated as a guarantee of restitution.

Can a Malicious Wallet Approval Be Revoked?

Some token approvals can be reviewed and revoked before the permission is used again.

The precise process depends on the blockchain, wallet and application involved. Users should rely on reputable wallet interfaces, established blockchain explorers or trusted technical support rather than clicking links sent by an unknown recovery provider.

Revoking an approval may prevent further transfers under that permission. It does not reverse transactions that have already taken place.

A wallet may also remain at risk where:

  • The private key or recovery phrase has been exposed
  • The device is compromised
  • Several malicious approvals exist
  • The victim continues interacting with the fraudulent platform
  • The fraudster has access to an exchange or email account

Where compromise is suspected, the user may need specialist advice about securing remaining assets and associated accounts.

Victims should never disclose a private key or recovery phrase to someone claiming they need it to revoke a permission or recover cryptocurrency.

What Evidence Should Victims Preserve?

Relevant information may disappear when websites, accounts or messaging profiles are removed.

Victims should preserve:

  • Their wallet addresses
  • Transaction identifiers
  • Token-approval transactions
  • Receiving wallet addresses
  • The fraudulent website address
  • Screenshots of the platform
  • Messages and emails
  • Telephone numbers and usernames
  • Exchange account records
  • Bank payments used to purchase cryptocurrency
  • Dates and amounts of transfers
  • Details of any later demands for fees
  • Security alerts or unauthorised transaction notifications

Where possible, original records should be retained rather than relying only on screenshots.

Victims should also avoid paying supposed taxes, release charges or recovery fees requested by the fraudster. Further demands are often part of the same scheme.

What Role Does Cryptocurrency Tracing Play?

Cryptocurrency tracing may help establish how assets moved after they left the victim’s wallet.

Analysis may identify:

  • The first receiving wallet
  • Subsequent transfers
  • Cryptocurrency conversions
  • Cross-chain movements
  • Associated approval contracts
  • Centralised exchange deposits
  • Other wallets linked through transaction patterns
  • Connections to funds taken from other victims

The work may also help distinguish a direct payment from a transfer carried out under a malicious token approval.

For a broader explanation of blockchain analysis, wallet attribution and the limitations of recovery, read Can Stolen Cryptocurrency Really Be Traced?.

Transaction mapping does not automatically identify the fraudster or establish that a displayed wallet balance remains available.

Attribution may depend on exchange records, bank information, communications, device evidence or legal disclosure.

Freezing, Seizure and Recovery Are Different

Operation Atlantic demonstrates the importance of using precise language.

Tracing involves mapping transactions and identifying relevant wallets, services and jurisdictions.

Attribution involves establishing who appears to control a wallet or account.

Freezing restricts dealings with assets. This may be carried out by an exchange, bank, court or authorised public body.

Seizure involves an authority taking legal control of property.

Recovery means that assets are returned, realised or applied for the benefit of someone legally entitled to them.

Private investigators may trace transactions and identify relevant entities. They do not independently freeze or seize cryptocurrency.

Solicitors may advise on disclosure, protective applications and claims. Courts, exchanges and public authorities decide whether legal or institutional restrictions can be imposed.

What Should Victims Do Next?

Anyone who believes they have approved a malicious transaction or lost cryptocurrency should act promptly.

Appropriate steps may include:

  1. Stop interacting with the suspected platform or fraudster.
  2. Review and secure the affected wallet and connected accounts.
  3. Preserve wallet, transaction and communication records.
  4. Notify any relevant cryptocurrency exchange or wallet provider.
  5. Contact the bank or payment provider where conventional funds were used.
  6. Report the matter to the appropriate fraud-reporting and law-enforcement channels.
  7. Consider legal advice where the value is substantial or an identifiable exchange holds relevant assets.
  8. Assess whether cryptocurrency tracing is proportionate.

Victims contacted by someone claiming to represent Operation Atlantic should independently verify the communication using the official NCA verification details. The NCA advises UK victims to report incidents through Report Fraud and quote Operation Atlantic where relevant.

Asset Tracing Services

Conflict International provides Asset Tracing Services for individuals, businesses, law firms and professional advisers dealing with cryptocurrency fraud and disputed digital assets.

Our work may include:

  • Blockchain transaction analysis
  • Review of token approvals
  • Wallet and transaction mapping
  • Identification of exchange touchpoints
  • Cross-chain transaction research
  • Connected-party and corporate enquiries
  • Clearly sourced reporting for legal and professional review

We distinguish confirmed blockchain activity from possible wallet attribution and explain where exchange, banking or legal disclosure may be required.

We do not promise that every wallet controller can be identified or that traced cryptocurrency will be frozen or recovered.

To discuss an approval-phishing or cryptocurrency asset-tracing matter, contact Conflict International with the available wallet, transaction and communication records.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a summary of the matter. (e.g. Investment fraud, breach of contract, unpaid judgment, or misappropriation of corporate funds).

What is the estimated total value of the assets to be recovered? (Please specify currency).

Provide known details of the individual or entity holding the assets. Include names, last known addresses, known associated companies, and any identified bank or crypto-wallet details.

Please confirm specific jurisdictions where you believe the assets may be held or where the subject has a physical presence?

Current Legal Status

Have you instructed Legal Counsel for this matter?

Identified Asset Classes

Select all that apply:

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite