What is a token approval, and how does it drain a wallet?
This one catches careful people, including people who correctly guard their seed phrase and use a hardware wallet. The seed was never stolen. The victim authorised the theft, weeks earlier, without understanding what they were signing.
Why approvals exist at all
Recall from Unit 1 that a token is a smart contract holding its own balance table. Your tokens are entries in that contract, not in your wallet.
So when an application — a decentralised exchange, a marketplace, a lending protocol — needs to move your tokens as part of its operation, it cannot simply take them. You must first call the token contract's approve(spender, amount) function, which records an allowance: permission for that specific contract to move up to that amount of that token out of your address.
Afterwards, the approved contract can call transferFrom at any time, up to the allowance, for as long as the allowance exists. There is no expiry.
The two things that make it dangerous
Unlimited allowances. Rather than ask you to approve every trade, most interfaces request the maximum possible number — 2²⁵⁶ − 1, an amount so large it is effectively infinite. It is a genuine convenience feature. It also means one signature grants permanent, total access to your entire balance of that token, present and future.
NFT operator approval. For collectibles, setApprovalForAll(operator, true) grants an address control over every item you own in that collection, forever, in a single call.
Signature-only grants. With EIP-2612 permit and Permit2, an allowance can be created by an off-chain signature — no transaction, no gas, no blockchain record at the time. The victim sees a prompt saying "sign this message", assumes it is a harmless login, and signs away an allowance. Blind-signing an opaque hexadecimal blob is the same act with less information.
The worked scenario
Your address holds 5,000 units of a stablecoin and some NFTs.
- You follow a link from a reply to a popular post to mint a collectible. The site looks correct.
- Your wallet shows a prompt. It says Approve, names a contract address you have never seen, and shows an amount rendered as "Unlimited" or a number with 78 digits.
- You confirm. The mint appears to fail or does nothing. You forget it.
- Seventeen days later the stablecoin balance is zero. The block explorer shows a
transferFromcall executed by that contract.
Every step was valid. The signature was yours. The chain did precisely what you told it to, and Unit 2's first lesson applies: there is nothing to reverse.
Note carefully: a hardware wallet does not prevent this. It protects the key from being extracted. It does not protect you from approving a hostile contract — you would have pressed confirm on the device.
The defences, in order of usefulness
- Read the verb. "Connect" is not "Sign", and "Sign" is not "Approve". Approve grants permission — and so do some signatures, because a
permitsignature is an allowance in the shape of a login prompt. Connect alone moves nothing. If a prompt asks you to approve or to sign something you cannot read, and you expected a login, stop. - Approve exact amounts where the interface allows it, so an allowance ends when the trade does.
- Audit and revoke. Setting an allowance to zero is just another
approvecall. Block explorers provide token-approval views listing every outstanding allowance on an address. Doing this periodically is basic hygiene. - Compartmentalise. Use one address for interacting with contracts and a separate address, which has never approved anything, for anything held long-term. An allowance can only reach the address that granted it.
Try it now
- On an Ethereum block explorer, open the token approvals view for any large, publicly known address. Scan the allowance column and find an entry displayed as unlimited.
- Click through to the
approvetransaction that created it and read the input data. Note the date — and that the permission has been live ever since. - Write the distinction in your own words: what is the difference between sending tokens and approving someone to send them? If you can explain it to someone else, you are ahead of most people who transact daily.