How to Revoke DApp Token Approvals Before They Drain Your Crypto Wallet

How to Revoke DApp Token Approvals Before They Drain Your Crypto Wallet

To remove a DApp’s access to your tokens, you have to find the approval it holds and revoke it in a separate on-chain transaction - disconnecting the DApp does not remove the permission, and your tokens stay exposed until the allowance is set to 0.

Key Takeaways

  • Approvals live on-chain - closing the app or the WalletConnect session changes nothing; the spending permission stays active until you revoke it.
  • Unlimited approvals raise the damage - a single unlimited permission lets a contract spend the token’s entire current and future balance.
  • Revoke prevents future spends, not past theft - resetting an allowance blocks new transfers but cannot recover assets a drainer has already moved.

What Are DApp Token Approvals?

A DApp token approval is a permission a wallet owner grants to a smart contract to spend a specific token up to a set amount. Without that approval, a decentralized exchange, lending market, or any other DApp cannot move your tokens - the approval is what lets it swap, stake, or transfer them on your behalf when you interact with it.

A smart contract is a blockchain-based program that automatically performs actions when predefined conditions are met.

How DApp Token Approvals Work

A token approval follows a fixed sequence: you connect your wallet to a DApp, the DApp requests an approval, it is recorded on-chain, and from then on the DApp performs the approved action without asking again. This is how well-known DApps like Aave and Uniswap work. Because the permission lives on the blockchain and not in the app session, it stays in force long after you stop using the DApp.

Approvals come in a few distinct forms:

  • Limited Approval: DApp can spend only the amount you set, for example 500 USDC, and must request a new approval to spend more.
  • Unlimited Approval: DApp can spend any amount of the chosen token, including tokens that arrive in your wallet later.
  • Token Approval: Smart contract receives permission to manage a specific fungible token, such as USDC or USDT.
  • NFT Approval: Permission can cover a single NFT or an entire collection, for example through setApprovalForAll.

Token approval does not reveal your secret phrase or give a DApp unrestricted access to the entire wallet. It applies only to the approved token, NFT, amount, and smart contract.

When Do Crypto Wallet Users Grant Token Approvals?

Token approvals appear during everyday DeFi actions: swapping tokens, lending, staking, and selling NFTs. They can stay active after the action is done or the DApp is disconnected.

Swapping Tokens on a DEX: Say you’re swapping USDC for ETH on Uniswap - first you approve the Permit2 contract (a permission manager by Uniswap Labs) to use USDC. An unlimited approval can stay active after the swap completes or is canceled.

Supplying Tokens to a Lending Protocol: To lend USDT on Aave, you approve the Aave Pool contract to move tokens out of the wallet. An unused allowance can remain after the deposit is withdrawn or the DApp is disconnected.

Staking Tokens Through a DApp: When staking through Aave Umbrella, you approve the staking contract to move the chosen tokens into the pool. If the approval exceeds the deposit, the leftover allowance can keep working after you exit staking.

Listing an NFT for Sale: List an NFT on OpenSea and the marketplace may request access to a single NFT or the entire collection through setApprovalForAll. A collection-wide approval stays in force until the user revokes it in a separate transaction.

Claiming Tokens From an Airdrop: A fake airdrop site can hide an unlimited approval or a Permit signature behind an ordinary Claim button. After you confirm, a wallet drainer can move the approved tokens or NFTs without any new request in the wallet.

What Are the Risks of Token Approvals?

The danger is not the approval itself but what it can turn into over time. Three risks matter most:

  • Unlimited Allowance: Contract can spend the entire current and future balance of the approved token, not just the amount you meant to use.
  • Lingering Approval: Permission keeps working for months or years after you last touched the DApp, so a forgotten approval stays exploitable.
  • Compromised Contract: Even a legitimate DApp can be hacked after you granted the approval, handing an attacker the access you already signed off.

What Are Crypto Wallet Drainers?

A crypto wallet drainer is a malicious tool that uses a phishing site or fake DApp to trick you into granting permission to transfer your tokens or NFTs. Instead of guessing your secret phrase, a drainer gets you to sign the access voluntarily, then uses it to move your most valuable assets out. Drainers are a large, active threat: they stole $494 million from about 332,000 wallet addresses in 2024, up 67% from the year before (Scam Sniffer, 2024).

How Wallet Drainers Exploit Token Approvals

A drainer attack usually runs through a predictable chain of steps:

  1. User lands on a fake mint, airdrop, or investment site.
  2. Site prompts the user to connect their wallet.
  3. User signs an approval or a permit signature.
  4. Drainer scans the wallet and identifies the most valuable assets.
  5. Approved tokens or NFTs are transferred out without any new confirmation.

Connecting a wallet alone does not let anyone move your assets - the danger begins only after you sign an approval or a malicious transaction. That single signature is the line between a harmless connection and a drained wallet.

Why Disconnecting a DApp Does Not Revoke Its Approval

Disconnecting and revoking are two different actions, and only one of them removes a contract’s spending permission. Disconnecting closes the interface between your wallet and the DApp; the approval keeps living on-chain.

ActionWhat It DoesWhat Remains Active
DisconnectCloses the connection between the wallet and the DApp interfacePreviously granted on-chain approvals
RevokeRemoves or resets the smart contract’s spending permissionThe DApp must request a new approval to access the token again

To show the difference, we connected Gem Wallet to the legitimate DApp Uniswap and granted Permit2 an unlimited approval on USDC. After disconnecting Uniswap, no active WalletConnect sessions remained, but Revoke.cash still showed the approval with the full USDC balance as value at risk. Disconnecting only closes the connection to the DApp - the on-chain approval stays until a separate revoke transaction.

Uniswap requesting unlimited USDC approval, Gem Wallet showing no active WalletConnect sessions, and Revoke.cash still listing one active approval Approve in Uniswap, disconnect the DApp - and the approval is still active on-chain in Gem Wallet.

How to Revoke DApp Token Approvals: Step by Step

Revoking an approval takes a few minutes. Here is the whole process at a glance:

  1. Open the approval checker.
  2. Enter your wallet address.
  3. Select the blockchain.
  4. Review active approvals.
  5. Revoke or reduce the allowance.
  6. Confirm the transaction.
  7. Verify the result.

Let’s go through each step in detail.

Step 1: Open a Trusted Approval Checker

Open an approval checker such as Revoke.cash or the Etherscan Token Approval Checker, and type the address yourself rather than following a link. Phishing copies of these tools exist, so double-check the domain before connecting anything.

Step 2: Enter Your Crypto Wallet Address

Start in read-only mode by pasting your public wallet address - this lets you see every active approval without connecting or signing. Connecting through WalletConnect is only needed once you are ready to revoke.

Step 3: Select the Correct Blockchain

Choose the network where the approval was granted, because each chain stores its own approvals. Ethereum, BNB Chain, Polygon, Base, and other networks must be checked separately - an approval on one chain is invisible on another.

Step 4: Review the Spender and Allowance

For each entry, check the token, the smart contract (spender), the approved amount, the date it was granted, and the value at risk. An unknown spender or an unlimited amount on a token you hold is the clearest sign an approval should go.

Step 5: Revoke or Reduce the Token Approval

Remove an approval you no longer need entirely, or reduce the allowance to the amount you actually plan to use. Tapping Revoke builds a transaction that resets the spending allowance for that contract to 0.

Step 6: Confirm the Transaction in Your Wallet

The request opens in your wallet, such as Gem Wallet, through WalletConnect. Before you confirm, check that:

  • Amount: Approved allowance changes to 0 USDC.
  • Contract: USDC.
  • Method: Approve.
  • Spender: Permit2.
  • Network: Ethereum.

Confirming requires a network fee (for example ETH), since this is the on-chain transaction that actually removes the permission. Approve it in Gem Wallet to send it.

Step 7: Verify That the Approval Was Removed

Reload Revoke.cash and confirm the approval is gone or its amount has changed. In our test, the dashboard updated to 0 approvals, $0 value at risk, and an empty approval list - proof the contract can no longer spend USDC until it asks again.

Tapping Revoke in Revoke.cash, confirming the 0 USDC allowance in Gem Wallet, and the dashboard verifying 0 approvals with no value at risk Tap Revoke, confirm the 0 USDC allowance in Gem Wallet, and verify the approval is gone.

Which Token Approvals Should You Revoke?

Not every approval needs removing, but some are clear candidates. Revoke an approval when:

  • Unused DApp: You no longer use the DApp that holds it.
  • Unknown Spender: You don’t recognize the spender contract.
  • Unlimited Amount: The approval was granted for an unlimited amount.
  • Old NFT Listing: The permission is tied to an NFT listing you’ve closed.
  • Reported Hack: The project has disclosed a hack or exploit.
  • Suspicious Source: The approval appeared after a questionable mint or airdrop.
  • Forgotten Reason: You can’t remember why you granted it in the first place.

What to Do If Your Crypto Wallet Has Already Been Drained

Revoke every active approval immediately: revoking stops further spending but will not recover assets that were already stolen. If your secret phrase or private key was exposed, create a new wallet on a clean device and move any remaining funds there. If a sweeper bot is watching the address, do not send gas to the compromised address without a separate asset-rescue plan.

How to Use DApps Without Getting Drained

Revoking cleans up the permissions you already granted - but the safer habit is catching a risky approval before you ever sign it. A few rules cover most cases:

  • Verify the Domain: Check the DApp’s exact URL before connecting.
  • Ignore Approval Bait: Don’t sign unclear approvals just to claim an airdrop.
  • Cap the Amount: Limit the approved amount instead of granting unlimited.
  • Watch for setApprovalForAll: Treat collection-wide NFT permissions with extra caution.
  • Check the Spender: Confirm the spender address belongs to the real protocol.
  • Prune Regularly: Remove old approvals on a schedule.
  • Isolate the Risk: Use a separate wallet for new and untrusted DApps.

Use DApps across 100+ blockchains with Gem Wallet - a fully open-source, self-custody wallet that stores private keys on your device and collects no personal data. Download Gem Wallet and connect to WalletConnect-compatible apps while keeping full control of your keys.

جرّب محفظة جيم!

محفظة ذاتية الحفظ لأكثر من 100 سلسلة كتل

App Store 4.9 ★ على متجر التطبيقات | Google Play 4.8 ★ على متجر جوجل بلاي
تحميل الآن

الأسئلة الشائعة

No - disconnecting closes the WalletConnect session, but the on-chain approval stays active until a separate revoke transaction.
Open Revoke.cash, find the approval by your public address, connect Gem Wallet through WalletConnect, and confirm the transaction that sets the allowance to 0.
No - once the allowance is set to 0, the smart contract must request a new approval before it can use the token again.
No - revoking blocks future spending, but it does not reverse transactions a wallet drainer has already made.
Yes - revoking is an on-chain transaction and requires a network fee in the chain's native token, such as ETH on Ethereum.