Law enforcement agencies in the U.S., U.K., and Canada launched Operation Atlantic to disrupt cryptocurrency fraud schemes based on approval phishing, in which victims are tricked into authorizing malicious wallet permissions through fake alerts, pop-ups, or spoofed service messages. Once a victim approves access, attackers can drain assets from the wallet, and recovery is difficult because blockchain transactions are generally irreversible. Authorities said the campaign responds to a broader rise in crypto-enabled fraud, with Chainalysis estimating at least $14 billion in on-chain scam revenue in 2025 and warning the total could rise as more illicit wallets are identified.
The operation builds on earlier anti-fraud efforts including Project Atlas, which identified more than 2,000 compromised wallets across 14 countries, disrupted roughly $70 million in potential fraud, and froze about $24 million in stolen cryptocurrency. The same threat pattern is reflected in phishing lures impersonating platforms such as OpenSea, where fake offer alerts, account verification notices, and token airdrop messages attempt to push users into connecting wallets to malicious sites. Those examples illustrate the social-engineering tactics now commonly used in approval-phishing campaigns, alongside increasingly sophisticated content and phishing-as-a-service infrastructure.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Authorities said Operation Atlantic identified more than 20,000 cryptocurrency fraud victims across Canada, the United Kingdom, and the United States. Investigators also froze over $12 million in suspected criminal proceeds and linked more than $45 million in stolen cryptocurrency to approval-phishing schemes worldwide.
As part of Operation Atlantic, officials including the U.S. Secret Service and the U.K. National Crime Agency urged crypto users to verify sources, enable multi-factor authentication, monitor account activity, avoid unsolicited investment offers, and use tools such as Etherscan and Revoke.cash. The guidance emphasized that approval-phishing scams are growing more sophisticated and that early action can help users secure their assets.
Law enforcement agencies in the United States, United Kingdom, and Canada launched Operation Atlantic to disrupt crypto approval-phishing scams that trick users into granting malicious wallet permissions. Authorities said the initiative would help identify victims, secure compromised wallets, trace stolen assets, and improve public awareness in coordination with private-sector partners.
Prior anti-fraud effort Project Atlas identified more than 2,000 compromised wallets across 14 countries and disrupted about $70 million in potential fraud tied to crypto scams. This earlier operation is cited as a precursor to later international enforcement activity against approval-phishing schemes.
A warning was published about phishing emails impersonating OpenSea, using lures such as fake NFT offers, transaction errors, account verification requests, and token airdrop claims to trick users into connecting wallets to malicious sites. The guidance said legitimate OpenSea emails come from official domains and do not ask users to download software, open attachments, or sign wallet transactions through email links.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcecoindesk.com
Open sourceonlinethreatalerts.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.