Token approvals and wallet drainers: how one signature can empty a wallet
To use most crypto apps you first give a smart contract permission to move your tokens. Scammers have learned to ask for that same permission. Here is how it works and how to stay in control.

Photo: “Key to the open door” by Tawheed Manzoor, CC BY 2.0, via Flickr (edited: cropped and resized).
A token approval lets a smart contract move your tokens later, without asking again [1]. A wallet drainer is a scam site that tricks you into approving — or signing a permit for — a contract the attacker controls, then uses that permission to take your tokens [1] [2].
Key points
- 1Approvals are normal: decentralised exchanges and lending apps need them to move your tokens on your behalf.
- 2An approval stays active until it is used up or revoked, and the approved contract can use it at any time.
- 3Unlimited approvals expose every token of that type you hold — now and later.
- 4A “permit” is an approval granted by signing a message, not by sending a transaction, so it can feel harmless. Permit2 brings the same idea to any ERC-20 token once you have approved the Permit2 contract.
- 5You can revoke approvals, but revoking cannot undo tokens that have already been taken.
On this page
- What is a token approval?
- Why are unlimited approvals risky?
- How do wallet drainers trick people?
- What is a permit signature, and why does it matter?
- Can you cancel a permit you have already signed?
- What is Permit2, and how is it different from a permit?
- How do you check and revoke approvals?
- What can revoking not fix?
- What mistakes do beginners make here?
- Frequently asked questions
- The bottom line
- Sources
What is a token approval?#
Many tokens on Ethereum follow a standard called ERC-20, which a later proposal describes as ubiquitous in the Ethereum ecosystem [2]. Besides sending tokens, the standard lets you approve another account to spend an amount of your tokens for you [3]. The approved account — usually a smart contract — can then call a function named transferFrom to move them, and a function named allowance reports how much permission remains [3].
This is how decentralised apps work. If you want to swap tokens on a decentralised exchange, you first give the exchange’s contract permission to move those tokens; NFT marketplaces and lending apps use the same pattern [1]. Ethereum.org notes that the approve-then-transferFrom pattern is the intended way to deposit ERC-20 tokens into contracts [3].
How an approval is used
Why are unlimited approvals risky?#
An approval is a standing permission. Revoke.cash, an approval-checking service, puts it plainly: if you give a smart contract permission to spend your tokens, it can spend them at any time, so if that contract is hacked or malicious, your tokens can be stolen [1]. Ethereum.org therefore advises against unlimited spend limits, because they could let a contract drain your wallet; set the limit to the amount the transaction needs instead [4].
| Step | Value |
|---|---|
| Tokens in the wallet | 1,000 |
| Exact approval for the swap | 100 |
| Allowance left after the swap uses it | 100 − 100 = 0 |
| Exposed if the contract is later hacked (exact) | 0 |
| “Unlimited” approval (largest possible number, 2²⁵⁶ − 1) | ≈ 1.16 × 10⁷⁷ |
| Exposed if the contract is later hacked (unlimited) | All 900 remaining, plus any you receive later |
The exact approval costs you one extra approval transaction next time you trade. The unlimited one saves that step but leaves the door open for as long as you hold the token.
| Approval | What it allows | What is exposed |
|---|---|---|
| Exact token approval | Spend up to the amount you set [1] | Only that amount, until used or revoked |
| Unlimited token approval | Spend any amount of that token [4] | Your whole balance of that token, now and later |
| Single NFT approval | Transfer one specific NFT [1] | That one NFT; cleared automatically when it is transferred |
| Collection-wide NFT approval (setApprovalForAll) | Transfer any NFT in the collection [1] | Every NFT you own from that collection |
How do wallet drainers trick people?#
“Wallet drainer” is the informal name for scam sites and kits built to collect these permissions. They rarely need your recovery phrase. Instead they get you to sign something. The common routes:
- Direct approval to the scammer. You are tricked into approving a contract the scammer controls, which then takes tokens straight from your wallet [1].
- Fake airdrops. Unknown tokens or NFTs appear in your wallet with a link to “claim” them. The claim site asks you to connect your wallet and approve a transaction that compromises your account or sends funds to the scammer [4].
- Zero-price listings. You are tricked into signing a message that lists your NFTs for sale for 0 ETH, which the scammer then “buys” [1].
- Look-alike links. Spoofed link previews and phishing emails send you to copies of real apps where the malicious request waits [4].
- Hacked legitimate apps. Even established projects get exploited; old approvals to a contract that is later hacked can be used against you [1].
What is a permit signature, and why does it matter?#
A standard called ERC-2612 adds a permit function to tokens. It lets a token’s allowance be set using a signed message instead of an approval transaction sent from your wallet [2]. Whoever holds your signed permit can submit it — the caller can be any address [2] — and you do not need to pay a network fee to sign it. That convenience is the danger: a request to “sign in” or “verify” on a scam site may in fact be a permit.
Revoke.cash adds some practical detail. Permit signatures are based on another standard, EIP-712, which defines a standard way to sign structured data [5]. The signed message is later passed to the token’s permit() function, which “activates” the approval on-chain; from then on it works like a regular approval [5]. Most tokens do not support ERC-2612 permits at all [5].
The permit message has a fixed set of fields, so a careful wallet can show you what you are granting [2]. Check them every time:
| Field | What it means | What to check |
|---|---|---|
| owner | Your address, granting the permission | That it is your own address |
| spender | Who receives the permission | That it is the app you meant to use, not an unknown address |
| value | How many tokens the spender may move | That it matches what you are doing, not a huge number |
| nonce | A counter that stops the same permit being reused | Nothing to do; it is set automatically |
| deadline | When the permit expires | A distant deadline means a long-lived permission |
Field names and meanings are from ERC-2612. The standard notes that a deadline can be set so that a permit effectively never expires [2].
Can you cancel a permit you have already signed?#
Sometimes. If you suspect you signed a permit on a scam site, you may be able to cancel it before the scammer activates it — but Revoke.cash says this is generally very hard, because scammers often try to activate the approval as soon as possible [5]. Once it has been activated, it can be revoked like any other approval [5].
There is a catch. Permits are signed off-chain, so a checking tool can never know for sure which ones you have signed; it can only show possible signatures [5]. Cancelling one you did not need to is not dangerous, but it wastes gas [5].
What is Permit2, and how is it different from a permit?#
Permit2 is a token approval system published in Uniswap’s permit2 code repository [6]. It is made of two smart contracts, AllowanceTransfer and SignatureTransfer [6]. Its main difference from an ERC-2612 permit is reach: any ERC-20 token, even one that does not support ERC-2612, can use permit-style approvals through it [6].
There is one on-chain step first. Before an app can request your tokens through Permit2, you must approve the Permit2 contract through that token’s own contract [6]. That is an ordinary token approval, given to Permit2 rather than to the app. After it, an app can send a permit signature along with its transaction data, so you do not need a separate approval transaction each time [6].
- AllowanceTransfer sets allowances. Your signature gives a spender permission over a specified amount for a specified duration of time [6]. Transfers through it only succeed if the proper permissions have been set [6].
- SignatureTransfer skips the allowance. You sign a message that transfers tokens directly to the spender named in it [6]. The permission lasts only for the transaction in which that one-time signature is spent [6].
- Batches. One signature can set permissions on different tokens for different spenders [6]. One signature can also transfer different tokens to different recipients [6].
- Expiry and clean-up. Permit2 approvals can be time-bound, and an approval that has expired is no longer valid [6]. Allowances on any number of tokens and spenders can be removed in one transaction [6].
How a Permit2 approval is used
| Method | Which tokens | What your signature does | How long it lasts |
|---|---|---|---|
| ERC-2612 permit | Only tokens that support it; most do not [5] | Becomes an approval once passed to the token’s permit() function [5] | After activation, like a regular approval [5] |
| Permit2 AllowanceTransfer | Any ERC-20, after you approve the Permit2 contract [6] | Sets an allowance for a spender [6] | For the duration set in the permission [6] |
| Permit2 SignatureTransfer | Any ERC-20, after you approve the Permit2 contract [6] | Transfers tokens directly to the signed spender [6] | Only the transaction that spends it [6] |
Before you sign a Permit2 request, check the spender, every token listed — one signature can cover several [6] — the amount and the expiry. To clean up afterwards, remember the two layers. The permissions you signed are Permit2 allowances, which can expire or be removed in one transaction [6]. The first approval you gave to the Permit2 contract is a normal token approval, and like any token approval it is revoked by calling approve again with the amount set to 0 [1].
How do you check and revoke approvals?#
- Approve only what you need
Set the spend limit to the amount for this transaction rather than unlimited; many wallets offer this option [4].
- Review your active approvals
Approval-checking tools read the approvals your address has granted and flag contracts known to have been exploited [1].
- Revoke what you no longer use
Revoking a token approval means calling approve again with the amount set to 0; for collection-wide NFT approvals, setApprovalForAll is called with false [1].
- Expect a small fee
A revoke is an ordinary transaction from your address, so it needs ETH for gas — unlike a permit, which only needs a signature [2]. See Ethereum gas fees.
- Make it a habit
Keeping approvals to a minimum and revoking regularly limits how much damage a scammer can do [1].
What can revoking not fix?#
Revoking removes a permission for the future. It cannot reverse tokens that have already moved — transactions on Ethereum are irreversible [4]. And if the problem is a leaked recovery phrase rather than an approval, revoking is beside the point: whoever has the phrase can access all of your accounts [4]. In that case the only protection is to move what remains to a new wallet with a new phrase. Read seed phrases explained for why.
Approvals at a glance
What mistakes do beginners make here?#
- Clicking “approve” on autopilot
Approval pop-ups look routine, which is exactly why scammers use them. Read the spender and amount every time.
- Thinking a signature is harmless because it is free
A signed permit or marketplace listing can hand over tokens or NFTs without any on-chain transaction from you.
- Interacting with surprise airdrops
Tokens you did not ask for are often bait. Do not visit the site they point to, and do not try to sell or “claim” them.
- Never cleaning up old approvals
An approval you granted years ago is still live. If that app is later exploited, the old permission can be used against you.
- Treating Permit2 requests as routine once you approved it
After the one-time approval to the Permit2 contract, later permissions arrive as messages to sign, not transactions. Read the spender, tokens, amount and expiry of each one.
Frequently asked questions#
Does revoking an approval cost money?
Yes, a small amount. Revoking is an on-chain transaction from your address, so it needs ETH to pay gas [2].
Is it safe to just connect my wallet to a website?
Connecting shares your address so the site can read your balance. The danger starts with what you sign or approve next. Treat every approval or signature request on an unfamiliar site as suspect [4].
Do approvals exist on Bitcoin?
Not in this form. Token approvals belong to smart-contract tokens such as ERC-20 on Ethereum and similar networks. Bitcoin’s risks are more about recovery phrases, phishing and wrong addresses.
If I move my tokens to a new wallet, are the old approvals still a risk?
Approvals are tied to the address that granted them. Tokens moved to a new address are not covered by the old address’s approvals, but anything you leave behind still is.
Can a wallet drainer take my ETH as well as tokens?
Approvals cover tokens and NFTs. A drainer can still take ETH if you are tricked into confirming a transaction that sends it, which is why some airdrop scams ask you to confirm a transfer to the scammer’s account [4].
Can a scammer send tokens from my address without any approval?
Only a zero-token transfer. Revoke.cash explains that a scammer can use a token’s transferFrom function to record a zero-value transfer from your address even though you gave no approval, because zero is never more than the approved amount [7]. Nothing leaves your wallet, but a look-alike address now sits in your history. This trick is called address poisoning; see common crypto scams.
Why does an app ask me to approve Permit2 first?
Permit2 needs one ordinary approval: before an app can request your tokens through it, you must approve the Permit2 contract through the token’s own contract [6]. After that, the app can send a signature with its transaction instead of asking for a separate approval transaction [6]. That first approval is a standing permission like any other: an approved contract can spend your tokens at any time [1]. So treat later Permit2 signature requests with the same care.
The bottom line#
Token approvals are the plumbing of decentralised finance: useful, routine and easy to stop thinking about. Wallet drainers exploit exactly that habit, using approvals and permit signatures to take tokens without ever needing your recovery phrase.
Approve only what you need, read what you sign, and clean up old permissions. For the wider landscape of tricks, read common crypto scams; to see what approvals make possible, start with how decentralised exchanges work.
Sources#
Grade A = primary source (regulator, protocol specification, client code, original author). Grade B = expert secondary source used for explanation only.
- BRevoke.cash. What Are Token Approvals?.
- AEthereum Improvement Proposals. ERC-2612: Permit Extension for EIP-20 Signed Approvals, 2020.
- Aethereum.org. ERC-20 Token Standard, 2026.
- Aethereum.org. Ethereum security and scam prevention, 2026.
- BRevoke.cash. What Are EIP2612 Permit Signatures?.
- AUniswap (GitHub repository). permit2 (README), 2026. README retrieved 3 October 2026.
- BRevoke.cash. What Is Address Poisoning?.


