Non-custodial · read-only

How approvals drain wallets

An approval doesn't move your tokens today, it gives a contract standing permission to move them whenever it wants. Here's how that permission turns into a drain, and how to find and revoke it first.

Scan your wallet: free Watch 24/7 on Telegram

Public address only. No wallet connection. Nothing to sign.

What an approval actually grants

Calling a token's approve(spender, amount) doesn't send anything. It writes a permission into the token contract: the spender may call transferFrom on your balance, up to amount, whenever it chooses, no further signature from you. Every swap, mint, and bridge asks for one before it can pull the token it needs.

Why unlimited is the default trap

Most dapps request the maximum possible amount so you never have to approve that spender again. It's convenient, and it's also a standing blank check: the allowance doesn't expire, doesn't shrink as you spend, and stays exactly as large the day you forgot the dapp existed as the day you signed it.

How a spender turns malicious

The spender doesn't have to be malicious from day one. Its contract can get exploited months later, its team can turn out to be a rug, or a scam token/farm can be malicious from the start, any of these lets someone call transferFrom on every wallet that still has an open allowance, no new approval required.

Find and revoke before it's used

Scan your public address to list every approval across chains, unlimited allowances and unverified or flagged spenders are highlighted, along with how long each has been sitting open. Revoke the risky ones on revoke.cash before a forgotten approval becomes someone else's payday.

FAQ

Does having an approval mean I've already been drained?

No. An approval is a standing permission, not a transfer. Nothing moves until the spender actually calls transferFrom, which is exactly why revoking it in advance works.

How do I know which approvals are risky?

Unlimited allowances to unverified or unknown contracts are the highest risk, followed by any spender flagged malicious or one you no longer recognize using. A scan surfaces all three automatically.

Related