Blockchain

UK-led Operation Atlantic has frozen $12 million in crypto

BlockchainApril 9, 2026·6 min read

A coordinated law enforcement operation across the UK, US, and Canada has frozen $12 million in cryptocurrency tied to approval phishing scams, identifying over 20,000 victims, a critical demonstration of cross-border asset recovery capabilities that institutional investors must monitor as regulatory coordination tightens around digital asset custody and exchange liability.

  • Operation Atlantic, led by the UK’s National Crime Agency, froze $12 million in suspected criminal proceeds across multiple platforms during a one-week March 2026 operation.
  • Authorities identified over 20,000 victims across the UK, US, and Canada, while discovering $45 million in total stolen cryptocurrency from approval phishing schemes globally.
  • Binance’s on-the-ground support identified scam accounts in real time without freezing any funds on its own platform, signaling exchange-regulator cooperation models still evolving.
  • $12 million in frozen assets across multiple platforms versus $45 million total theft identified globally
  • 20,000+ victims identified across UK, US, Canada compared to prior single-jurisdiction enforcement actions
  • 120 malicious web domains disrupted during the week-long operational period

Three major law enforcement jurisdictions have successfully recovered and frozen digital assets tied to approval phishing scams at a scale that rivals traditional financial crime seizures.

Operation Atlantic, a joint effort coordinated by the United Kingdom’s National Crime Agency with participation from US and Canadian authorities, recovered $12 million in suspected criminal proceeds across various cryptocurrency platforms and protocols during a single week in March 2026.

The operation identified more than 20,000 victims across the three countries and uncovered a global theft total of $45 million in cryptocurrency, establishing approval phishing as one of the highest-impact fraud vectors in digital assets today.

Approval phishing exploits user behavior rather than protocol vulnerabilities, making it particularly dangerous at scale.

The scam operates through a deceptively simple social engineering attack: criminals send victims fake alerts or pop-ups purporting to originate from legitimate cryptocurrency applications or investment platforms. The messages claim a security issue or investment opportunity requires wallet access approval.

Once a victim signs the malicious blockchain transaction, the attacker gains permanent permission to withdraw tokens at will, effectively draining the wallet over time or in a single transaction.

Unlike traditional password theft, approval attacks grant ongoing access without requiring the victim’s private key, making detection and wallet recovery extremely difficult for users and creating a persistent vulnerability window that investigators must close before further drains occur.

Binance’s Real-Time Intelligence Role Reveals Exchange-Regulator Intelligence Sharing Model

Binance deployed its Special Investigations Team to the National Crime Agency’s London headquarters during the operational week, providing live account screening and victim identification support.

The exchange’s role departed from traditional asset freezing: Binance identified which wallet addresses connected to scam schemes in real time, flagged malicious websites still actively defrauding victims, and supplied intelligence on suspected fraudulent actors and their blockchain addresses to support law enforcement seizure efforts.

However, the company did not freeze any customer funds on its own platform, suggesting either that scam proceeds had not been deposited to Binance wallets or that the exchange’s cooperation model prioritizes intelligence sharing over unilateral asset control.

This operational structure raises important questions about institutional exchange liability and regulatory expectations around real-time law enforcement cooperation.

Binance’s presence at the NCA command center and its capacity to provide pseudonymous transaction analysis demonstrates that exchanges now function as embedded intelligence partners in multinational operations, not merely as account holders subject to post-hoc freezing orders.

For institutional investors evaluating exchange risk, this signals that platforms with active compliance teams and direct law enforcement channels may face greater operational transparency demands but also benefit from first-mover asset recovery advantages.

The pseudonymous nature of blockchain transactions, which Binance helped to decode through address clustering and behavioral analysis, remains the core technical challenge for law enforcement. Without exchange cooperation, investigators cannot easily trace stolen funds from victim wallets to deposit addresses or identify scam operator accounts on centralized platforms.

Binance’s role in bridging that gap, translating on-chain data into actionable account intelligence, establishes a template that other major exchanges will likely be expected to replicate, creating a new operational compliance baseline for the industry.

Over 120 Malicious Domains Shut Down Reveals Scale of Infrastructure Supporting Phishing Ecosystem

Operation Atlantic identified and disrupted 120 web domains actively hosting approval phishing schemes, indicating that the scam infrastructure extends well beyond individual fraudsters to organized technical networks.

These domains typically hosted cloned versions of legitimate cryptocurrency exchange or wallet interfaces, designed to collect victim credentials or trick users into signing malicious transactions.

The discovery that law enforcement could enumerate and disable 120 active fraud domains in a single week suggests both the scale of the phishing ecosystem and the relative ease with which fraudsters can spin up replacement infrastructure using cheap domain registration services and hosting providers with weak abuse reporting processes.

The one-week timeframe within which this infrastructure was mapped and actionable suggests that the operation likely tracked scam campaigns in real time or worked from existing intelligence databases maintained by the three participating jurisdictions.

Coordinating domain takedowns across the UK, US, and Canada also required rapid legal process and hosting provider cooperation, indicating that law enforcement has developed streamlined procedures for crypto-specific fraud cases.

For institutional investors, the scale of domain disruption underscores that phishing attacks are not boutique criminal activities but organized, infrastructure-dependent schemes requiring sustained technical and financial investment from fraudsters.

Individual victim losses documented during the operation illustrate the personal impact underlying aggregate statistics: one UK victim lost £52,000 (approximately $66,000) to a single approval phishing attack. Multiplied across 20,000 identified victims, this suggests an average loss in the thousands of pounds per person, though aggregate losses undoubtedly vary widely.

The fact that such substantial individual losses could occur despite the victim’s apparent access to regulated custody solutions raises questions about whether victims were using self-custody wallets, decentralized finance platforms, or other non-custodial solutions that law enforcement cannot easily freeze or reverse.

Cross-Border Asset Freezing Establishes Precedent for Multinational Crypto Enforcement Coordination

The $12 million in frozen assets represents one of the largest coordinated cryptocurrency asset seizures executed by law enforcement across multiple jurisdictions simultaneously.

Freezing proceeds across “various platforms and protocols” indicates that the operation tracked stolen funds beyond a single exchange or blockchain, requiring investigators to coordinate across both centralized custodians and decentralized protocol interactions.

This coordination model departs from previous single-jurisdiction or single-platform enforcement actions, establishing a new operational standard for high-impact fraud cases.

The distinction between the $12 million in frozen assets and the $45 million in identified thefts is operationally significant: it reveals that law enforcement successfully traced less than 27 percent of stolen cryptocurrency.

The remaining $33 million either remains in circulation, has been converted to fiat currency through unregulated exchanges or peer-to-peer sales, or has been moved to privacy-enhanced protocols that resist blockchain analysis.

For institutional crypto investors, this gap highlights the limitations of even coordinated law enforcement efforts when confronted with actively managed fraud proceeds and sophisticated money laundering techniques.

The operation’s timing in March 2026 places it within a period of elevated regulatory focus on cryptocurrency fraud following multiple high-profile exchange collapses and custody failures.

Coordinating asset freezes across three separate legal jurisdictions required harmonized legal authority, mutual legal assistance frameworks, and pre-established relationships between law enforcement agencies.

The National Crime Agency’s leadership of Operation Atlantic suggests that the UK has positioned itself as a central node in multinational crypto enforcement networks, likely leveraging London’s role as a global financial center and existing anti-money laundering infrastructure.

US and Canadian participation indicates that enforcement agencies in North America view cross-border phishing operations as a shared threat requiring coordinated response rather than parallel investigations.

Approval Phishing Victims and Hidden Custody Risks Shape Exchange Liability Exposure

The 20,000-victim identification across three countries indicates that approval phishing has become a mass-market attack, not a niche fraud affecting only advanced cryptocurrency users. Victims appear to span custody arrangements, experience levels, and demographic profiles, suggesting that the scam succeeds through psychological manipulation and social engineering rather than exploitation of technical knowledge gaps. This breadth of victimization creates regulatory pressure on exchanges and custodians to

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe