Illustration of a wallet with an exposed spending approval

Every interaction with a decentralized application typically asks a wallet to approve that application spending a specific token on its behalf. Many of these approvals are granted for an unlimited amount by default, and most are never revoked once the original interaction is finished with.

Why an old approval is still a live risk

A contract that was safe when the approval was first granted does not necessarily stay safe. If that contract is later compromised or maliciously upgraded, a forgotten approval can be used to drain the wallet with no further action required from the owner. This is one of the more common mechanisms behind decentralized finance losses we see in our case data.

A short, repeatable process

  • Open a reputable wallet interface or blockchain explorer that includes an approvals management view.
  • Review the full list of active approvals, not just recent ones.
  • Revoke anything tied to an application you no longer use, recognize, or trust.
  • Repeat this every few weeks for an actively used wallet, rather than only after something feels wrong.
Key Point

This is a preventative habit, not a response to an active incident, but it remains one of the few genuinely effective steps available to any wallet holder without specialist tools.

token approvalsdefi securitywallet security

Related reading

Spotting a Fraudulent DeFi Contract Before You DepositThree Scam Structures Behind Most Crypto Investment Losses