Skip to content
Wallets & SecurityBeginner

Malicious token approvals: what they are and how they work

A malicious token approval is a permission you sign that lets a scammer move a token from your wallet later. Revoking it takes another transaction.

Vahe HakobyanVahe HakobyanEditor-in-chief Updated Oct 5, 20263 min readFact-checked
A blank hardware wallet, a steel plate and a padlock on a dark navy desk lit by glowing red light, with the left side dark and empty.
Illustration: World-Crypt
On this page

Short answer

A malicious token approval is a permission you sign that lets a scammer's contract spend a token from your wallet. The attacker often waits and uses it later.

Token approvals are normal for blockchain apps. A malicious request hides that permission behind a fake page or a copied token.

How to check and revoke token approvals

You can review every approval your wallet has granted with an approval checker or a block explorer. Each entry lists the spender, the token, and the amount.

Review and revoke an approval

  • Open an approval checker and paste your public wallet address.
  • Compare each spender with apps you use.
  • Revoke approvals you do not recognize and confirm each transaction.

How to spot a malicious approval request

Legitimate apps ask for an approval before they can move a token for you. Read the pop-up inside your wallet, which names the spender, the token, and the amount.

How do token approvals work?

An approval writes an allowance into the token contract. That allowance records how much a named spender may move from your address. Apps need that allowance because the token contract only lets the owner or an approved spender move tokens. An unlimited approval lets the spender move your entire balance of that token.

A standard approval does not move tokens by itself. It only changes the allowance for the app.

How is it different from a wallet drainer?

A normal transaction moves an asset. A malicious approval grants a permission the attacker may use later.

What each request does
Point Normal transaction Malicious approval Wallet drainer
What you sign A transfer you intend A permission you did not intend A run of requests in one visit
When funds move When the transaction confirms Later, when the attacker uses it During the attack

Frequently asked questions

No. Once it confirms, it cannot be reversed. You can revoke the allowance with a new transaction.

It covers the token and the spender named in the request. Any other token keeps its own allowance.

The contract sets that spender's allowance to zero, so it can no longer move that token. Revoking does not return tokens already moved.

Was this guide helpful?
Written byVahe HakobyanVahe Hakobyan is the editor-in-chief of World-Crypt. He covers bitcoin, markets and regulation, and leads the newsroom that fact-checks every story before it goes live.