Inside an Investment Scam Operation: Chainalysis Unveils the Mechanics of Global Approval Phishing Networks

The digital asset landscape is currently grappling with a sophisticated and rapidly evolving threat known as approval phishing, a tactic that has transformed investment scams from isolated incidents into industrialized criminal enterprises. According to recent data from Chainalysis, a leading blockchain analysis firm, on-chain scams accounted for at least $14 billion in illicit activity throughout…

 Avatar

by

8 minutes

Read Time

The digital asset landscape is currently grappling with a sophisticated and rapidly evolving threat known as approval phishing, a tactic that has transformed investment scams from isolated incidents into industrialized criminal enterprises. According to recent data from Chainalysis, a leading blockchain analysis firm, on-chain scams accounted for at least $14 billion in illicit activity throughout 2025. This figure is projected to climb as high as $17 billion as further addresses are identified and attributed to criminal entities. The alarming growth of this sector is underscored by a 253% year-on-year increase in the average payment made to a single scam address, a trend exacerbated by the integration of artificial intelligence, which has reportedly made AI-augmented scams 4.5 times more profitable than traditional methods.

To address this escalating crisis, Chainalysis recently launched "Chain of Thought," an expert-hosted webinar series designed to provide law enforcement, compliance professionals, and the public with a behind-the-scenes look at real-world investigations and emerging crypto crime trends. The inaugural session, "Inside an Investment Scam Operation," featured Chainalysis investigators Seth DuBois and Renato Bastos, who dissected an active approval phishing operation. Their analysis revealed a complex ecosystem where social engineering meets technical exploitation, highlighting the critical need for coordinated international intervention.

The Technical Anatomy of Approval Phishing

Approval phishing differs significantly from traditional "carpet-bombing" phishing attacks that aim to steal login credentials or private keys. Instead, this technique exploits a fundamental feature of smart contracts: the "approval" function. In legitimate decentralized finance (DeFi) transactions, a user must approve a decentralized application (dApp) to spend a specific amount of tokens from their wallet. This is a standard procedure for trading on decentralized exchanges or participating in lending protocols.

In an approval phishing scam, the malicious actor tricks the victim into signing a transaction that grants the scammer’s address permission to spend an unlimited number of tokens from the victim’s wallet. Because the victim is often presented with an interface that looks like a legitimate investment platform or a minor administrative task, they frequently overlook the "infinite approval" permission they are granting.

Renato Bastos explained that once this approval is secured, the scammer gains the power to drain the victim’s assets at any time. "The scammer might move instantaneously or lurk until an ideal moment, such as immediately after the victim deposits fresh funds from an exchange," Bastos noted. This "lurking" strategy allows criminals to maximize their haul, waiting for the victim’s balance to reach a peak before executing the drain. Once the funds are moved, they are rapidly cycled through a series of intermediary wallets, cross-chain bridges, and eventually to high-volume exchanges to be converted into fiat currency.

The Social Engineering Playbook: The Human Element

The technical execution of approval phishing is almost always preceded by a lengthy social engineering campaign. These operations often fall under the category of "pig butchering" (Sha Zhu Pan), where scammers build a rapport with victims over weeks or months before introducing a fraudulent investment opportunity.

Chainalysis investigators have identified consistent red flags that often appear before the technical theft occurs. These include the use of "tethered" communication, where victims are moved from public social media platforms to encrypted messaging apps like Telegram or WhatsApp. Scammers often use scripts that combine romantic interest with "insider" financial advice, creating a sense of exclusivity and urgency. Compliance professionals at centralized exchanges are increasingly being trained to look for these behavioral patterns—such as a sudden increase in deposits followed by withdrawals to unknown self-custody wallets—as a means of intervention before the "approval" is ever signed.

Chronology of Global Disruption: Operations Spincaster, DeCloak, and Atlantic

The fight against approval phishing has moved from reactive investigations to proactive, large-scale operations involving international cooperation. The timeline of these efforts demonstrates a growing capability among law enforcement to track and seize illicitly obtained digital assets.

Operation Spincaster (2024)

In 2024, Chainalysis launched Operation Spincaster, a pioneering initiative that brought together law enforcement agencies and private sector partners from six different countries. The operation focused on "sprints"—intensive periods of data sharing and lead generation. During these sessions, over 7,000 leads were processed, enabling investigators to identify and disrupt approval phishing rings responsible for approximately $162 million in losses. One notable success involved a proactive warning to a victim who was in the process of being targeted; with the assistance of law enforcement, the individual revoked the scammer’s approval, saving a six-figure sum in cryptocurrency.

Approval Phishing: From Just One Case to Full-Scale Disruption

Operation DeCloak (Canada)

Following the success of Spincaster, localized operations began to emerge. In Delta, British Columbia, local police participated in Operation DeCloak. This initiative targeted scam infrastructure within a specific geographic jurisdiction, proving that even municipal police forces can effectively trace and freeze digital assets when equipped with the right on-chain intelligence. Operation DeCloak resulted in the freezing and eventual return of funds to several victims, challenging the common misconception that blockchain transactions are entirely beyond the reach of the law once completed.

Operation Atlantic (UK, US, Canada)

One of the most significant multi-jurisdictional efforts to date is Operation Atlantic. Led by the United Kingdom’s National Crime Agency (NCA), the United States Secret Service (USSS), the Ontario Provincial Police (OPP), and the Ontario Securities Commission (OSC), this operation identified more than 20,000 victims across three nations. By utilizing Chainalysis data, officials were able to identify at-risk wallets and freeze over $12 million in suspected criminal proceeds. Furthermore, an additional $45 million in stolen crypto was traced to related schemes, providing a roadmap for future seizures.

Data-Driven Insights and Infrastructure Reuse

A central theme of the Chain of Thought webinar was the predictability of criminal behavior on the blockchain. While scammers may change their social engineering scripts, they frequently reuse their technical infrastructure. This reuse is the "Achilles’ heel" of modern crypto-crime.

"Because the criminals reuse infrastructure, the typology becomes a query you can automate," explained Seth DuBois. Scammers often use the same "spender" contracts across thousands of victims. They also tend to consolidate stolen funds into a small number of "consolidation wallets" before attempting to cash out at specific exchange deposit addresses. By mapping these persistent nodes in the network, investigators can create "standing capabilities"—automated systems that alert exchanges and law enforcement the moment a known scammer’s wallet interacts with the broader ecosystem.

The data also highlights the industrialization of these scams. The fact that AI-augmented operations are significantly more profitable suggests that criminal syndicates are using large language models (LLMs) to manage hundreds of victim conversations simultaneously, maintaining the "human touch" at a scale previously impossible.

Strategic Shifts in Fraud Prevention

The investigators highlighted four critical shifts that are necessary to disrupt the approval phishing model effectively:

  1. Upstream Detection: Moving the point of intervention from the "cash-out" phase to the "social engineering" and "approval" phases.
  2. Rapid Lead Pivoting: Reducing the time it takes for a victim report to reach an investigator who can take action on-chain.
  3. Collaborative Networks: Plugging into global disruption networks like those established during Operation Spincaster to ensure that a scammer blocked in one jurisdiction cannot easily move to another.
  4. In-House Expertise: Building specialized crypto-investigative units within traditional law enforcement and financial institutions.

For retail users, DuBois emphasized a common-sense security checklist: verifying URLs before connecting wallets, avoiding app downloads from unofficial links in group chats, and exercising extreme caution when a stranger creates a sense of financial urgency.

Implications for the Future of Decentralized Finance

The rise of approval phishing has significant implications for the regulatory and technical future of the cryptocurrency industry. There is growing pressure on wallet providers and dApp developers to improve user interface (UI) transparency. Many wallets have already begun implementing warnings when a user is about to sign an "infinite approval" or an "increase allowance" transaction, but the data suggests that social engineering can often bypass these technical hurdles.

Furthermore, the success of operations like Atlantic and Spincaster demonstrates that the "pseudonymity" of the blockchain is a double-edged sword. While it allows for privacy in legitimate transactions, it provides a permanent, immutable record for investigators. The ability to trace $45 million in stolen assets across multiple borders proves that the "standing capability" of law enforcement is catching up to the speed of digital crime.

As approval phishing operations become more methodical and automated, the global response must mirror that sophistication. The transition from ad hoc investigations to a unified, data-driven defense network is no longer a luxury but a necessity for the continued growth and institutional adoption of digital assets. The findings from the "Chain of Thought" series serve as a stark reminder that while the blockchain is irreversible, the networks that exploit it are increasingly visible and vulnerable to coordinated disruption.

About the Author

About the Author

Easy WordPress Websites Builder: Versatile Demos for Blogs, News, eCommerce and More – One-Click Import, No Coding! 1000+ Ready-made Templates for Stunning Newspaper, Magazine, Blog, and Publishing Websites.

BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor

Search the Archives

Access over the years of investigative journalism and breaking reports