How to Revoke Token Approvals Before They Drain You
Most wallet losses are not stolen keys. They are approvals granted months ago to a contract that later turned hostile — and revoking them takes about a minute.
Most wallet losses are not stolen keys. They are approvals granted months ago to a contract that later turned hostile — and revoking them takes about a minute.

A token approval gives a smart contract standing permission to move that token out of your wallet, and unlimited approvals never expire. Review them at a revocation tool such as revoke.cash or Etherscan's token approval checker, revoke anything you are not actively using, and set custom spending limits instead of unlimited ones. Revoking costs gas but cannot lose funds.
The mental model most people carry — my crypto is safe as long as nobody has my seed phrase — is wrong in one specific and expensive way. Every time you swap on a decentralised exchange, list an NFT, or deposit into a vault, you sign an approval that lets a contract move that token from your wallet. The approval does not expire when you close the tab. It sits there until you remove it.
ERC-20 tokens do not let a contract take tokens from you directly. Instead you call `approve`, naming a spender contract and an amount. From then on, that contract can call `transferFrom` and move up to that amount whenever it likes, without asking you again.
Interfaces have historically requested an unlimited amount, because it saves the user a second transaction on every future swap. The convenience is real and so is the exposure: an unlimited approval to a contract that is later upgraded, compromised or was malicious from the start means everything of that token in your wallet can leave in one transaction.
NFT approvals work the same way, with a worse variant. `setApprovalForAll` grants a contract permission over an entire collection, which is why a single careless signature on a phishing site can empty a wallet of every NFT in one go.
Open a revocation tool — revoke.cash and Etherscan's token approval checker are the two most used, and both are read-only until you choose to revoke. Connect the wallet, or simply paste the address to review without connecting at all, which is the safer habit.
You will see a list of spender contracts, the token each can move, and the allowance. Sort by allowance and look at the unlimited ones first. For each, ask a single question: am I still using this protocol? An approval to a DEX router you swapped through once in 2023 has no reason to exist.
Revoke by sending a transaction that sets the allowance to zero. It costs gas — a few cents on an L2, more on Ethereum mainnet — and it cannot lose funds, because the only thing it does is reduce someone else's permission over your tokens.
Approvals are per chain and per token. A clean Ethereum mainnet list says nothing about what you granted on Arbitrum, Base, BNB Chain or Polygon. Most revocation tools switch networks in the interface; work through every chain where you have transacted, and pay particular attention to chains you experimented on and abandoned, since those are where forgotten approvals accumulate.
Two habits remove most of the future risk. First, set a custom allowance rather than accepting unlimited: approve roughly what you intend to spend, and accept one extra signature next time. Several wallets expose this as an editable field on the approval screen.
Second, use a wallet that shows you what the approval does before you sign it. Rabby simulates the transaction and states plainly which token a contract will be able to move and how much — the single most useful safety feature available to an EVM user, and the reason it leads our wallet ratings.
For balances that matter, keep the keys on a hardware wallet. It does not prevent you approving something hostile, but it forces the approval onto a screen you have to read, and it removes the class of attack where malware signs on your behalf.
Revoking stops future transfers. It does not undo one that has already happened, and it does not help if the attacker has your private key rather than an allowance. If tokens have already moved, treat the wallet as compromised: move remaining assets to a fresh wallet created on a clean device, and do not reuse the seed phrase.
One more trap: some drainer sites ask for a `permit` or `permit2` signature rather than an on-chain approval. These are off-chain signatures that authorise a transfer, they cost no gas, and they will not appear in an allowance list until they are used. The defence is the same — read what you are signing, and be suspicious of any site asking for a signature you did not initiate.
The order of operations decides how much you keep. Most people revoke first, which is the step that loses them the rest.

Creator royalties were once pitched as NFTs' killer feature over traditional art. A few years and one marketplace price war later, most of that promise has quietly evaporated — here's how NFT royalties actually work and why enforcement collapsed.

Smart contracts can't see the outside world on their own. Oracles are the systems that feed them prices, events, and data — and getting that design wrong has cost DeFi protocols hundreds of millions.