Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case filesmart contract risk

Revoking Token Approvals: A Walkthrough

Five minutes on a block explorer, done monthly, closes the largest open exposure most crypto users have.

Priya Raman · 2 min read

Every contract you have ever granted permission to move your tokens still has that permission, unless you have revoked it. Most people have dozens of live approvals and have never looked.

Why it matters

An approval does not expire. One granted in 2023, to a protocol you used once, is live today.

If that contract is later compromised, or was malicious from the start and simply waited, the approval is all it needs. No further action from you is required.

This is the mechanism behind a large share of wallet drains, and it is entirely preventable with a monthly review.

The walkthrough

Step one. Open a block explorer for the chain your wallet is on. The major ones all have a token approval tool, usually linked from the address page.

Step two. Enter your address. You do not need to connect a wallet to view the list.

Step three. Read the list. Each row shows the token, the contract holding the approval, and the approved amount. Unlimited approvals are usually labelled as such.

Step four. Sort by value at risk, where the tool supports it. This shows which approvals could actually cost you something, which is the correct priority order.

Step five. Revoke what you do not currently use. Revocation requires connecting your wallet and signing a transaction, and each one costs a network fee.

Step six. Repeat for every chain you have used. Approvals are per chain and the lists are separate.

What to revoke

Anything you do not recognise. If you cannot remember granting it, revoke it.

Anything unlimited that you use occasionally. Re-approving when needed costs a transaction and removes standing exposure.

Everything on a protocol you have stopped using.

Everything on any protocol that has had a security incident, regardless of whether you were affected.

What to keep

Approvals on protocols you actively use, ideally for specific amounts rather than unlimited.

There is a real trade-off: revoking and re-approving costs fees. For someone interacting daily, keeping a limited approval is reasonable. For someone who used a protocol once, it is not.

Doing it cheaply

Revocations cost gas and are never urgent, so batch them and do them at a quiet time. Weekend mornings are consistently cheapest.

On layer 2 networks the cost is negligible.

The structural version

The reason to do this monthly is that it reduces standing exposure. The reason it stays manageable is a separate wallet for connecting to sites.

If your connecting wallet holds a small balance, its approvals matter less. If your long-term wallet has never connected to anything, it has no approvals at all.

That arrangement makes the monthly review a five-minute task on one wallet rather than an audit across everything, and the funds that would actually hurt to lose are not in the list at all. The working balance at an exchange you can actually contact has no approvals either, because there is no key to approve with.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

approvalsrevocationpractical

Related cases