Approval phishing: how to check wallet permissions before tokens are drained
A practical guide to wallet approvals: how allowances differ from wallet connections, what to check before signing, and when to revoke old permissions.
What is approval phishing, and why is it more dangerous than “connecting a wallet”?
Approval phishing is an attack where a user is pushed into signing a permission, not merely visiting a site or connecting a wallet. The permission can allow a contract to spend tokens later. That is why wallet safety is not only about never sharing a seed phrase; it is also about reading who gets access, to which token, and for what amount.
Why does disconnecting a site not solve the problem?
A wallet connection and a token allowance are different things. A connection usually lets a site see your public address and request actions. An approval or allowance can give a smart contract the right to move a specific token within the approved limit.
MetaMask explains that disconnecting a dApp is not the same as revoking an allowance, and that revocation is an on-chain transaction that costs gas: MetaMask Help Center. The practical takeaway is simple: if you signed a suspicious approval, “disconnect” is not a fix.
What does a normal approval look like?
A normal approval is tied to a clear action. A DEX may need access to USDC to execute a swap, or a protocol may need access to an LP token to add liquidity. Even then, check three fields: the token, the spender contract, and the limit.
The awkward trade-off is unlimited approval. It saves clicks and gas for repeated use, but it increases damage if the contract is malicious or later compromised. For a one-time action, a limited approval close to the needed amount is usually safer than giving access to the full balance.
What are the signs of approval phishing?
The first sign is urgency: “claim a reward,” “verify your account,” “private sale,” “refund,” or “urgent airdrop.” The second sign is a mismatch between the promise and the wallet screen: the website says login or confirmation, while the wallet shows a spend limit, setApprovalForAll, or token access.
A third sign is human coaching. In a June 17, 2026 analysis, Chainalysis describes approval phishing as part of broader social engineering: victims are guided step by step, pushed to depend on a supposed mentor, and rushed into transactions. The same article says on-chain scams received at least $14 billion in 2025, potentially rising to $17 billion as more illicit addresses are attributed: Chainalysis.
What should you check before signing?
Check the domain: it should be the official site, not a similar address from an ad, direct message, or search result. Check the action in the wallet: are you confirming a swap, signing a message, or approving token spending? Check the amount: if you need to swap 100 USDC, unlimited access to the full balance should not pass automatically.
Also check the contract. For known protocols, spender addresses can often be verified through documentation, a block explorer, or the official interface. If the site is new, the contract is not verified, transaction history is thin, or documentation is weak, close the page and return later.
How should you clean up old permissions?
Once a month, or after an active DeFi period, open an approval checker in a block explorer or a dedicated permission tool. MetaMask lists several ways to track and revoke allowances, including MetaMask Portfolio, block explorers, and external tools. Revoke.cash explains approvals as permissions that let smart contracts spend tokens on your behalf and provides educational material on managing them: Revoke.cash Learn.
The cleanup rule is simple: keep only the permissions you still need. Old approvals to unknown protocols, test sites, forgotten NFT marketplaces, and one-off farms are good candidates for revocation. It costs gas, but it reduces the attack surface.
What if you already signed a suspicious approval?
First, do not sign anything else on that site. Open an approval checker from a bookmark or a manually typed address, not from a chat link. Find the newest approval for the relevant network and token, then revoke it. If you add gas and it disappears immediately, the problem may be a compromised seed phrase or private key, not only an allowance.
Revoke.cash notes in its FAQ that revoking approvals cannot recover stolen assets and does not fix a wallet whose seed phrase has been compromised; in that case, you need a new wallet and a safe migration of any remaining assets: Revoke.cash FAQ.
What is a practical security setup?
Use one wallet for storage that does not connect to new sites. Use a separate hot wallet with a small balance for experiments. For every new protocol, limit the spend amount when the wallet and interface allow it. After a one-time action, remove the extra permission.
Another useful rule: if a site creates urgency, asks for screenshots, introduces a “manager,” or sends you through a direct-message link, stop. Good interfaces do not need to rush a user who is trying to understand what they are signing.
What are the limits of this approach?
Checking approvals reduces risk, but it does not make DeFi safe. It does not protect against price drops, protocol vulnerabilities, frontend compromise, fake tokens, user mistakes, or seed phrase theft. It is a hygiene layer, not a guarantee. Its value is narrower: it removes unnecessary open-ended permissions and forces a pause before signing a transaction that cannot be reversed.
Sources
- Chainalysis approval phishing
- MetaMask approvals
- Revoke.cash approvals
This article is for information only and is not individual investment advice. Trading crypto carries the risk of losing your funds; results on historical data do not guarantee future results.
Check the strategy against your own data
ACARO is a terminal that executes a strategy on your own exchange account. Parameter search and backtesting on history are part of the subscription.
See pricing