Skip to content

September 3, 2026

CRYPTO·COINBEAT

Journalism for the digital-asset economy

BTC$67,240 2.4%/
ETH$3,418 1.1%/
SOL$182.40 0.8%/
BNB$604.20 0.3%/
XRP$0.624 1.9%/
ADA$0.512 0.6%/
AVAX$38.10 3.2%/
DOGE$0.158 0.4%/
BTC$67,240 2.4%/
ETH$3,418 1.1%/
SOL$182.40 0.8%/
BNB$604.20 0.3%/
XRP$0.624 1.9%/
ADA$0.512 0.6%/
AVAX$38.10 3.2%/
DOGE$0.158 0.4%/
Ethereum· Analysis

Token Approvals: The Quiet Way Wallets Get Drained

By Maria Fernandez

DeFi Protocols & RWA On-Chain AnalystDeFi Protocols & RWA On-Chain Analyst · September 3, 2026 · 9 min read

Published September 3, 2026 · Reviewed to our editorial standards. This article is informational and not financial advice.

Token Approvals: The Quiet Way Wallets Get Drained
Illustration · Ethereum

When a wallet is emptied on Ethereum or another EVM chain, the private key has usually not been stolen. Something more ordinary happened: the owner granted a contract permission to move their tokens, and that permission was still valid weeks or years later when someone decided to use it.

Understanding approvals is the difference between using decentralised applications safely and using them hopefully. The mechanism is simple, the default settings are dangerous, and the fix takes ten minutes.

What an approval actually is

Token standards on EVM chains do not let a contract take your tokens directly. Instead, you call the token's approve function, naming a spender contract and an amount. From then on, that contract may transfer up to that amount from your wallet, at any time, without asking again.

This is what makes trading on a decentralised exchange possible: the router needs permission to move the token you are selling. The problem is not the mechanism, it is the amount and the duration. Many interfaces request an effectively unlimited allowance, because it saves the user a transaction on every subsequent trade — and that allowance does not expire.

Why this is the attacker's favourite tool

An approval signature often costs no gas, produces no visible change in your balance, and looks identical to the confirmations you approve routinely. A malicious site does not need to steal anything at the moment you interact with it. It needs one signature, and patience.

The drain then happens at a time of the attacker's choosing — frequently long after you have forgotten the site existed, which is why victims so often report that they "did not do anything" that day. They did not. They did something months earlier.

Permit signatures: the version with no transaction at all

Newer token standards support gasless approvals, where you sign a structured message rather than send a transaction. The user experience is better and the risk profile is worse: there is no pending transaction to inspect, no gas prompt to give you pause, and the signature can grant a spender the same powers.

Treat any request to sign a message you cannot read as equivalent to handing over the tokens it names. A wallet that decodes these into plain language before signing is doing the single most valuable safety job available — the capability we weight most heavily in our self-custody wallet table.

How to audit what you have already granted

Every approval you have ever made is public, because it was an on-chain transaction. Several tools list them per address and let you revoke in one click, and most block explorers include an approval checker.

  • Go through every address you use, not just the main one — the forgotten wallet is where old approvals accumulate.
  • Revoke anything you no longer use, and anything granted to a site you cannot identify.
  • Reduce unlimited allowances on contracts you do use to an amount you would be comfortable losing.
  • Repeat quarterly. Approvals accumulate silently and there is no notification when one is used.

Revoking costs a small amount of gas per token per contract, which is why people put it off. Price that against the balance the approval covers and it is the cheapest insurance available on-chain.

The structural fix: separate addresses

Auditing helps. Architecture helps more. Keep long-term holdings in an address that has never interacted with a decentralised application, and do all on-chain activity from a separate wallet holding only what you are actively using.

Then an approval mistake costs you the contents of the spending wallet rather than your savings. This is the same split described in our crypto security guide, and it is the single most effective change most people can make.

If you think you already signed something bad

Speed matters more than diagnosis. Move any remaining balance to a fresh wallet first, before working out what happened — an approval you have not identified is still live while you investigate, and attackers frequently drain in stages rather than all at once.

Then revoke every approval on the compromised address, including tokens you no longer hold, because an allowance persists for future deposits. Treat that address as burned for anything valuable: if the key itself was exposed rather than just an approval, revocation does nothing at all, and there is no way to tell the two apart from the outside.

Finally, reconstruct the sequence from the block explorer. Every approval and transfer is public and timestamped, which usually makes the entry point obvious — and knowing which site it was tells you what else you may have connected with the same wallet.

What good practice looks like

  • Use a wallet that simulates transactions and shows resulting balance changes before you sign.
  • Edit unlimited approvals down to the amount you are actually trading, where the interface allows it.
  • Sign from a hardware device for anything meaningful, and read the decoded details on its screen.
  • Keep savings in an address that never connects to anything, as covered in custodial vs non-custodial wallets.
  • Run a revocation pass every quarter, across every address.

None of this makes decentralised applications risk-free. It moves the worst case from "everything I own" to "what was in the hot wallet", which is the distinction that decides whether a bad signature is an annoyance or a catastrophe.

One last point worth internalising: an approval is not a payment and produces no immediate change you can see, so there is no moment where your balance visibly drops and prompts you to investigate. The absence of feedback is precisely what lets a hostile allowance sit undisturbed for a year. Assume nothing will alert you, and put the quarterly audit in a calendar where you will actually see it.

Frequently asked questions

What does revoking a token approval do?+

It sets the allowance you granted a contract back to zero, so it can no longer move that token from your wallet. It does not undo transfers already made, which is why the timing of the audit matters.

Why are unlimited approvals dangerous?+

Because they persist indefinitely and cover your entire balance of that token. A contract that turns malicious, or was malicious from the start, can use the permission at any point in the future without asking again.

Does revoking approvals cost gas?+

Yes, a small amount per token per contract, since it is an on-chain transaction. Compared with the balance an unlimited approval exposes, it is the cheapest protection available.

Is a signature request the same as an approval?+

It can be. Gasless permit signatures grant the same spending powers without a transaction or a gas prompt, which makes them harder to spot. Never sign a message you cannot read in plain language.

Written by

Maria Fernandez

DeFi Protocols, Real-World Assets, On-Chain Analytics, Stablecoins, Spanish-Language Coverage

Maria Fernandez is an On-Chain Research Analyst at **CRYPTO·COINBEAT**, specializing in real-world asset (RWA) tokenization, decentralized finance, and stablecoin ecosystems. Originally from Mexico City and now based in Miami, Maria brings a unique Latin American perspective to blockchain research, combining deep technical analysis with insights into emerging digital asset markets across the Americas. Before joining **CRYPTO·COINBEAT**, Maria spent several years researching decentralized finance protocols, producing in-depth analysis on lending platforms, governance systems, and the growing adoption of tokenized real-world assets. Her early research into institutional RWA integration and decentralized collateral models helped explain one of the fastest-growing sectors within the blockchain industry. Maria's analytical approach combines on-chain transaction analysis, protocol revenue metrics, liquidity monitoring, and governance activity to evaluate the long-term health of DeFi ecosystems. She works extensively with blockchain analytics platforms, including Dune Analytics, Nansen, and Flipside Crypto, and has created numerous public dashboards that simplify complex blockchain data for investors and researchers alike. Her coverage of stablecoin market events and liquidity shifts has helped readers better understand risk during periods of heightened market volatility. She holds a B.Sc. in Industrial Engineering from ITAM (Instituto Tecnológico Autónomo de México) and a Graduate Certificate in FinTech from MIT Sloan. Passionate about blockchain education, Maria regularly contributes both English- and Spanish-language research, helping make advanced on-chain analysis more accessible to a global audience while supporting the continued growth of crypto adoption throughout Latin America.

Keep Reading

Proof of Stake and ETH Staking Explained
Ethereum· 10 min

Proof of Stake and ETH Staking Explained

Ethereum secures itself with staked ETH instead of mining. Here is how validators, rewards and slashing work, and what staking really involves.

David Turner · May 16, 2026