Terenval Answers · P1 safety · Русская версия
How Do Token Approval Scams Drain Crypto Wallets?
A token-approval scam does not always need your seed phrase. It can trick you into authorizing a spender contract to move a token from your wallet later.
Last reviewed: 2026-10-05.
Published by Terenval
Technical review: Terenval Wallet team
Editorial policy
Key takeaways
- Approval is a permission, not merely a login step.
- An unlimited allowance can remain valid until it is changed or revoked.
- The approval generally applies to a specific token and spender, not automatically every asset.
- Disconnecting the dApp does not erase an on-chain allowance.
- A compromised spender contract can turn an old approval into future risk.
1. The ERC-20 allowance model
ERC-20 defines approve(spender, value), allowance(owner, spender) and transferFrom. This enables legitimate workflows such as DEX swaps where a contract needs permission to pull tokens from the user's account.
The same mechanism becomes dangerous when a user is tricked into granting permission to an attacker-controlled or compromised spender.
2. How the drain happens
A phishing site or malicious dApp can present an approval as part of a claim, swap or verification flow. If the user approves a very high amount, the spender receives durable on-chain permission for that token.
The attacker can then trigger transfers up to the approved amount. A wallet password prompt at the time of the later token movement is not necessarily required because the token contract is honoring the permission that was already signed.
3. What to check before approving
- Exact blockchain network.
- Token contract.
- Spender contract.
- Allowance amount.
- Whether the requested action actually needs an approval.
- Whether the domain and contract match official dApp documentation.
Prefer the smallest practical allowance when the application and wallet support it. Be cautious when a simple claim or verification asks for unlimited spending power.
4. What to do after a suspicious approval
Use a trusted block-explorer approval checker or an independently verified revoke tool on the correct network. Revoke or reduce the allowance with an on-chain transaction and verify the result after confirmation.
If unauthorized transfers have already started or the seed/private key may also be compromised, approval revocation alone may not be enough. A migration to fresh recovery material may be required.
Common mistakes
- Treating Approve as a harmless connection button.
- Signing an unlimited allowance for a one-time action without reading it.
- Disconnecting WalletConnect and assuming the allowance is gone.
- Clicking an unsolicited “revoke your wallet now” link after a scare message.
- Leaving old unlimited approvals indefinitely on high-value accounts.
How this works in Terenval Wallet
When Terenval Wallet receives a transaction or signature request from a connected dApp, review what is being authorized before signing. WalletConnect does not make the requested contract trustworthy, and Terenval cannot undo an allowance already recorded on-chain.
Keep experimental dApp activity separate from large savings where practical, and revoke stale or suspicious allowances using verified on-chain tools.
Official pages: Supported networks · Security
Open Terenval WalletFrequently asked questions
Can an approval drain BTC?
ERC-20 approvals apply to token contracts on EVM networks; native Bitcoin does not use the ERC-20 allowance model.
Does an approval give access to all tokens?
Usually it authorizes a specific spender for a specific token contract and amount. Other signature types can have broader effects, so inspect the exact request.
Does changing my wallet password revoke approvals?
No. On-chain allowances remain until they are changed on-chain.
Related Terenval Answers
Primary and authoritative sources
- https://eips.ethereum.org/EIPS/eip-20
- https://support.metamask.io/more-web3/learn/how-to-revoke-smart-contract-allowances-token-approvals/
- https://ethereum.org/reports/trillion-dollar-security/
- https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-token-approval/
Terenval-specific statements are first-party; general technical claims are checked against primary or authoritative sources.