Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Crypto

How to Revoke Token Approvals on Your Crypto Wallet

Interacting with dApps creates token approvals, which can be exploited by hackers. Learn why these permissions are a security risk and how to fix it.

By · Published · 11 min read

A hand removes a key from a large, organized keyring, creating a newly empty slot.

Revoking token approvals is a crucial security step to protect your cryptocurrency from theft. You can do this by using a trusted allowance checker tool, such as Etherscan's Token Approval Checker or Revoke.cash, to review and cancel the permissions you've granted to decentralized applications (dApps). This process requires signing a new transaction on the blockchain to reset the approval to zero.

What Are Token Approvals?

When you use a decentralized exchange (DEX), NFT marketplace, or lending protocol, you aren't sending your tokens directly to the platform. Instead, you grant its smart contract permission to access and move a certain amount of a specific token from your wallet. This permission is called a token approval or allowance.

Think of it like giving a valet a key to your car. You're not giving them the title or ownership, just the ability to move the car on your behalf within certain parameters. The smart contract needs this permission to execute trades or other actions for you. For example, when you want to sell 100 USDC on a DEX, you first approve the DEX's router contract to be able to pull up to 100 USDC from your wallet. When you execute the swap, the contract takes the USDC and sends you the other token in return.

This system is fundamental to how most dApps on Ethereum and other EVM-compatible chains (like Polygon, Avalanche, and BNB Chain) function. It applies to different token standards:

  • ERC-20: The standard for fungible tokens like stablecoins (USDT, USDC) and governance tokens (UNI, AAVE).
  • ERC-721 & ERC-1155: The standards for non-fungible tokens (NFTs). Approving an NFT collection allows a marketplace's contract to transfer your NFTs when you list them for sale.

This approval mechanism is an essential piece of Web3 infrastructure, but it also creates a significant, and often overlooked, security risk.

The Hidden Danger of 'Unlimited' Approvals

For the sake of convenience, the vast majority of dApps prompt you to sign an unlimited approval. This means you are granting the smart contract permission to spend the *entire balance* of that specific token in your wallet, now and in the future. You do one transaction, and you never have to approve that token for that dApp again. While convenient, this is extremely dangerous.

An unlimited approval is a permanent permission slip. If that dApp's smart contract ever contains a vulnerability, is exploited through a flash loan attack, or has its administrative keys stolen, attackers can leverage that pre-existing unlimited approval to drain every single token of that type from your wallet. You don't need to be using the dApp at the time; the permission is always active on the blockchain until you revoke it.

This isn't a theoretical threat. Attackers frequently exploit old or forgotten approvals to steal funds. A famous case saw an exploit in a crypto payment processor drain NFTs from users who had granted approvals to the platform in the past, even if they hadn't used it recently. These older permissions were exactly what the attackers needed to execute the thefts, as was detailed in the Magic Eden payment processor exploit where old approvals were abused. It is also the primary mechanism behind many phishing scams involving crypto wallet drainer scripts, which trick users into signing a malicious approval transaction.

Leaving unlimited approvals active is like leaving signed, blank checks lying around. A thief just needs to find one and fill in the amount.

How to Check Your Active Approvals

You cannot easily view or manage token approvals from within a standard wallet interface like MetaMask. You must use a specialized third-party tool, often called an "allowance checker" or "revoker." It's critical to only use well-known, reputable tools for this process, as you will be connecting your wallet to them.

Trusted Allowance Checkers

For Ethereum and EVM-compatible chains, the most trusted tools are:

  • Etherscan (or other block explorers): Every major block explorer (like Polygonscan, BscScan, etc.) has a built-in Token Approval Checker. This is often the safest option, as it's provided by the same entity that provides the official block explorer.
  • Revoke.cash: A widely respected, open-source tool dedicated to managing approvals across dozens of chains. It has a clean interface and is a community standard for crypto security.

Step-by-Step Guide to Checking

  1. Navigate to the Tool: Go to the official website for Etherscan's Token Approval Checker or Revoke.cash. Always double-check the URL to avoid phishing sites. Bookmarking the correct site is a good practice.
  2. Connect Your Wallet: Click the "Connect to Web3" or similar button. Your browser wallet (e.g., MetaMask) will pop up and ask for permission to connect. This step is read-only; it only allows the site to see your public wallet address.
  3. Select the Network: Ensure you are on the correct blockchain network (e.g., Ethereum Mainnet, Polygon) that you want to check.
  4. Review Your Approvals: The tool will automatically scan the blockchain and display a list of all active token approvals associated with your address. The list will typically show you:
  5. - The Asset (the token you approved).
  6. - The Spender (the smart contract you gave permission to).
  7. - The Allowance (the amount, often shown as "Unlimited").

You might be shocked at how many approvals you have active, especially for dApps you haven't used in months or years.

A Step-by-Step Guide to Revoking Approvals

Once you have the list of your active approvals, you can begin cleaning them up. The goal is to revoke any permissions that are no longer necessary, especially unlimited ones to contracts you don't actively use.

  1. Identify the Approval to Revoke: Look through the list for any approvals you don't recognize, for dApps you no longer trust or use, or any unlimited approval you want to remove as a precaution.
  1. Initiate the Revocation: Next to the approval you want to cancel, there will be a "Revoke" button. Clicking this will prompt your wallet to initiate a new transaction.
  1. Sign the Transaction: Your wallet will pop up with a transaction for you to approve. This transaction is calling the `approve` function on the token's contract, setting the allowance for the spender to zero. This action overwrites and cancels the previous approval. You will need to pay a small transaction fee (gas) for this, which varies depending on network congestion.
  1. Confirm on the Blockchain: Once you confirm the transaction in your wallet, it will be sent to the blockchain. After it is confirmed by the network (usually in a few seconds to a minute), the approval will be permanently revoked. You can refresh the allowance checker page to verify that it's gone.

Some tools may also offer an "Update" option to change an unlimited approval to a specific, smaller amount. However, for old and unused permissions, revoking is the safest and most direct action.

Best Practices for Approval Hygiene

Revoking approvals shouldn't be a one-time event. It's a key part of ongoing wallet security hygiene. By adopting good habits, you can significantly reduce your risk exposure.

HabitGood Practice (Low Risk)Bad Practice (High Risk)
Approval AmountApprove only the exact amount needed for a trade.Granting "unlimited" approval every time.
Review FrequencyCheck and revoke unused approvals monthly.Never checking approvals after granting them.
Wallet UsageUsing a separate, low-value wallet for new dApps.Connecting your primary "hodl" wallet to every site.
Transaction SigningCarefully reading the transaction details before confirming.Blindly approving all wallet pop-ups.

Beyond these habits, it's crucial to learn how to spot a phishing email or malicious website, as many scams are designed specifically to trick you into signing a malicious approval transaction.

What Revoking Can't Protect You From

While revoking approvals is a powerful security measure, it's not a complete shield. It's important to understand its limitations.

Revoking approvals cannot protect you if your private key or seed phrase is compromised. If an attacker steals your seed phrase—whether through malware, a fake wallet app, or a social engineering scam—they have direct control over your account. They don't need to worry about smart contract approvals; they can simply sign a transaction to transfer all of your assets to their own wallet. This is why protecting your seed phrase is the single most important rule in crypto security.

The best way to secure your private keys is with a hardware wallet. By keeping your keys offline, these devices make it nearly impossible for online attackers to access them. They provide a much higher level of security than software wallets, which is why it's important to understand the difference between hot vs cold crypto wallets.

Furthermore, revoking approvals won't stop you from falling for a new phishing scam tomorrow. It only cleans up past permissions. The best defense is a combination of proactive hygiene and ongoing vigilance.

Adopting a Zero-Trust Approach

In the world of self-custody, you are your own bank, and that means you are also your own head of security. A "zero-trust" mindset is not paranoia; it's a practical necessity. Don't implicitly trust any dApp, link, or signature request. Verify everything and minimize the permissions you grant.

Make checking your token approvals a regular part of your financial routine, just like reviewing a bank statement. The few cents or dollars you spend on gas fees to revoke a dozen old approvals is an incredibly small insurance premium to pay when it protects you from the catastrophic loss of your entire crypto portfolio.

Read next