Beginner · 7 min read

How to Revoke Token Approvals Before They Drain You

Most wallet losses are not stolen keys. They are approvals granted months ago to a contract that later turned hostile — and revoking them takes about a minute.

Dario FennDario FennDeFi & Markets Lead · DeFi protocols, yield, market structure and on-chain data
How to Revoke Token Approvals Before They Drain You
The short answer

A token approval gives a smart contract standing permission to move that token out of your wallet, and unlimited approvals never expire. Review them at a revocation tool such as revoke.cash or Etherscan's token approval checker, revoke anything you are not actively using, and set custom spending limits instead of unlimited ones. Revoking costs gas but cannot lose funds.

The mental model most people carry — my crypto is safe as long as nobody has my seed phrase — is wrong in one specific and expensive way. Every time you swap on a decentralised exchange, list an NFT, or deposit into a vault, you sign an approval that lets a contract move that token from your wallet. The approval does not expire when you close the tab. It sits there until you remove it.

What you are actually signing

ERC-20 tokens do not let a contract take tokens from you directly. Instead you call `approve`, naming a spender contract and an amount. From then on, that contract can call `transferFrom` and move up to that amount whenever it likes, without asking you again.

Interfaces have historically requested an unlimited amount, because it saves the user a second transaction on every future swap. The convenience is real and so is the exposure: an unlimited approval to a contract that is later upgraded, compromised or was malicious from the start means everything of that token in your wallet can leave in one transaction.

NFT approvals work the same way, with a worse variant. `setApprovalForAll` grants a contract permission over an entire collection, which is why a single careless signature on a phishing site can empty a wallet of every NFT in one go.

The three-minute audit

Open a revocation tool — revoke.cash and Etherscan's token approval checker are the two most used, and both are read-only until you choose to revoke. Connect the wallet, or simply paste the address to review without connecting at all, which is the safer habit.

You will see a list of spender contracts, the token each can move, and the allowance. Sort by allowance and look at the unlimited ones first. For each, ask a single question: am I still using this protocol? An approval to a DEX router you swapped through once in 2023 has no reason to exist.

Revoke by sending a transaction that sets the allowance to zero. It costs gas — a few cents on an L2, more on Ethereum mainnet — and it cannot lose funds, because the only thing it does is reduce someone else's permission over your tokens.

Do this per chain, not once

Approvals are per chain and per token. A clean Ethereum mainnet list says nothing about what you granted on Arbitrum, Base, BNB Chain or Polygon. Most revocation tools switch networks in the interface; work through every chain where you have transacted, and pay particular attention to chains you experimented on and abandoned, since those are where forgotten approvals accumulate.

Stop creating the problem

Two habits remove most of the future risk. First, set a custom allowance rather than accepting unlimited: approve roughly what you intend to spend, and accept one extra signature next time. Several wallets expose this as an editable field on the approval screen.

Second, use a wallet that shows you what the approval does before you sign it. Rabby simulates the transaction and states plainly which token a contract will be able to move and how much — the single most useful safety feature available to an EVM user, and the reason it leads our wallet ratings.

For balances that matter, keep the keys on a hardware wallet. It does not prevent you approving something hostile, but it forces the approval onto a screen you have to read, and it removes the class of attack where malware signs on your behalf.

When revocation is not enough

Revoking stops future transfers. It does not undo one that has already happened, and it does not help if the attacker has your private key rather than an allowance. If tokens have already moved, treat the wallet as compromised: move remaining assets to a fresh wallet created on a clean device, and do not reuse the seed phrase.

One more trap: some drainer sites ask for a `permit` or `permit2` signature rather than an on-chain approval. These are off-chain signatures that authorise a transfer, they cost no gas, and they will not appear in an allowance list until they are used. The defence is the same — read what you are signing, and be suspicious of any site asking for a signature you did not initiate.

FAQ

Does revoking a token approval cost money?
Yes, it is an on-chain transaction and costs gas — cents on a layer-2, more on Ethereum mainnet. It cannot lose funds: it only reduces a contract's permission over your tokens.
How often should I check token approvals?
Monthly is a reasonable cadence for an active wallet, and immediately after using any unfamiliar dapp. Wallets like Rabby surface standing approvals in the interface, which makes the check routine rather than a chore.
What is an unlimited token approval?
An allowance set to the maximum possible value, letting a contract move that token from your wallet without limit, indefinitely. It saves a transaction on future swaps and is the reason many drains are total rather than partial.
Can I revoke approvals on all chains at once?
No. Approvals are per chain, so you have to review each network separately. Forgotten chains from past experiments are where the riskiest old approvals usually sit.