---
content_id: 25
content_type: evergreen-answer
priority: P1
intent: safety
cluster: security-scams
language: en
title: "How Do Token Approval Scams Drain Crypto Wallets?"
slug: token-approval-scams-drain-wallets
canonical: https://wallet.terenval.com/answers/token-approval-scams-drain-wallets/
primary_query: "how token approval scams drain crypto wallets"
last_reviewed: 2026-10-05
publisher: Terenval
---

# How Do Token Approval Scams Drain Crypto Wallets?

## Direct answer

ERC-20 approvals let a token owner authorize a spender contract to use tokens through an allowance. A malicious dApp can trick a user into approving a large or unlimited allowance; the attacker can later use `transferFrom` through the authorized spender to move those tokens without asking for a new approval each time. The seed phrase can remain secret while the approved token is still exposed. Review the spender, token and allowance before signing and revoke suspicious approvals on-chain.

## Key takeaways

- Approval is a permission, not merely a login step.
- An unlimited allowance can remain valid until it is changed or revoked.
- The approval generally applies to a specific token and spender, not automatically every asset.
- Disconnecting the dApp does not erase an on-chain allowance.
- A compromised spender contract can turn an old approval into future risk.

## 1. The ERC-20 allowance model

ERC-20 defines `approve(spender, value)`, `allowance(owner, spender)` and `transferFrom`. This enables legitimate workflows such as DEX swaps where a contract needs permission to pull tokens from the user's account.

The same mechanism becomes dangerous when a user is tricked into granting permission to an attacker-controlled or compromised spender.

## 2. How the drain happens

A phishing site or malicious dApp can present an approval as part of a claim, swap or verification flow. If the user approves a very high amount, the spender receives durable on-chain permission for that token.

The attacker can then trigger transfers up to the approved amount. A wallet password prompt at the time of the later token movement is not necessarily required because the token contract is honoring the permission that was already signed.

## 3. What to check before approving

- Exact blockchain network.
- Token contract.
- Spender contract.
- Allowance amount.
- Whether the requested action actually needs an approval.
- Whether the domain and contract match official dApp documentation.

Prefer the smallest practical allowance when the application and wallet support it. Be cautious when a simple claim or verification asks for unlimited spending power.

## 4. What to do after a suspicious approval

Use a trusted block-explorer approval checker or an independently verified revoke tool on the correct network. Revoke or reduce the allowance with an on-chain transaction and verify the result after confirmation.

If unauthorized transfers have already started or the seed/private key may also be compromised, approval revocation alone may not be enough. A migration to fresh recovery material may be required.

## Common mistakes

- Treating Approve as a harmless connection button.
- Signing an unlimited allowance for a one-time action without reading it.
- Disconnecting WalletConnect and assuming the allowance is gone.
- Clicking an unsolicited “revoke your wallet now” link after a scare message.
- Leaving old unlimited approvals indefinitely on high-value accounts.

## How this works in Terenval Wallet

When Terenval Wallet receives a transaction or signature request from a connected dApp, review what is being authorized before signing. WalletConnect does not make the requested contract trustworthy, and Terenval cannot undo an allowance already recorded on-chain.

Keep experimental dApp activity separate from large savings where practical, and revoke stale or suspicious allowances using verified on-chain tools.

## Frequently asked questions

### Can an approval drain BTC?

ERC-20 approvals apply to token contracts on EVM networks; native Bitcoin does not use the ERC-20 allowance model.

### Does an approval give access to all tokens?

Usually it authorizes a specific spender for a specific token contract and amount. Other signature types can have broader effects, so inspect the exact request.

### Does changing my wallet password revoke approvals?

No. On-chain allowances remain until they are changed on-chain.

## Sources

- https://eips.ethereum.org/EIPS/eip-20
- https://support.metamask.io/more-web3/learn/how-to-revoke-smart-contract-allowances-token-approvals/
- https://ethereum.org/reports/trillion-dollar-security/
- https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-token-approval/

## Editorial review

Published by Terenval. Technical review: Terenval Wallet team. Last reviewed: 2026-10-05.

## Related Terenval Answers

- [How Do Fake Crypto Wallet Support Scams Work?](https://wallet.terenval.com/answers/fake-crypto-wallet-support-scams/)
- [What Is Address Poisoning and How Can It Trick Crypto Wallet Users?](https://wallet.terenval.com/answers/address-poisoning-crypto-wallet-users/)
- [What Is Clipboard Hijacking in Crypto and How Do You Prevent It?](https://wallet.terenval.com/answers/clipboard-hijacking-crypto-prevention/)
- [How Can You Tell a Fake Crypto Wallet App from a Real One?](https://wallet.terenval.com/answers/how-to-tell-fake-crypto-wallet-app-from-real/)

Editorial policy: https://wallet.terenval.com/editorial-policy/

Official article: https://wallet.terenval.com/answers/token-approval-scams-drain-wallets/
