Malicious token approvals: what they are and how they work
A malicious token approval is a permission you sign that lets a scammer move a token from your wallet later. Revoking it takes another transaction.

On this page
Token approvals are normal for blockchain apps. A malicious request hides that permission behind a fake page or a copied token.
How to check and revoke token approvals
You can review every approval your wallet has granted with an approval checker or a block explorer. Each entry lists the spender, the token, and the amount.
How to spot a malicious approval request
Legitimate apps ask for an approval before they can move a token for you. Read the pop-up inside your wallet, which names the spender, the token, and the amount.
How do token approvals work?
An approval writes an allowance into the token contract. That allowance records how much a named spender may move from your address. Apps need that allowance because the token contract only lets the owner or an approved spender move tokens. An unlimited approval lets the spender move your entire balance of that token.
A standard approval does not move tokens by itself. It only changes the allowance for the app.
How is it different from a wallet drainer?
A normal transaction moves an asset. A malicious approval grants a permission the attacker may use later.
Frequently asked questions
No. Once it confirms, it cannot be reversed. You can revoke the allowance with a new transaction.
It covers the token and the spender named in the request. Any other token keeps its own allowance.
The contract sets that spender's allowance to zero, so it can no longer move that token. Revoking does not return tokens already moved.






