A token approval is a permission you grant a smart contract to move a set amount of your tokens without asking again. Grant an unlimited approval, and that contract can drain your entire balance in one transaction, months after you forgot it existed. This is the core of token approvals security: knowing what you've authorized and cutting off what you don't need.
The fix is straightforward even if the mechanics get technical fast:
- Pull up your approval history right now using your wallet's built-in checker or a block explorer.
- Flag anything unlimited, unfamiliar, or tied to a dApp you stopped using months ago.
- Revoke it. This requires sending an on-chain transaction, which means paying gas fees for each individual revocation.
There's no bulk, one-click cleanup. Each risky approval you clear costs a small transaction fee, and that's a fair trade for closing a door an attacker could otherwise walk through.
Key Takeaways
Token approvals security depends on treating every allowance as a standing liability that needs regular review, not a one-time setup step.
| Point | Details |
|---|---|
| Unlimited approvals are the default risk | Most dApps request unlimited allowances for convenience, which raises your exposure if that contract is ever compromised. |
| ACT vulnerabilities are widespread | Academic research found over 32,000 potentially vulnerable contracts tied to approve-transferFrom exploits. |
| Signature phishing skips the transaction | Gasless permit flows mean an attacker only needs your signature, not a visible on-chain approval. |
| Revoking costs gas every time | There's no free bulk revoke; each cleared allowance is its own on-chain transaction. |
| OmniRout reduces redundant approvals | Its non-custodial routing shows fees and slippage upfront, cutting down on repeat trial swaps that generate extra allowances. |
Table of Contents
- How Do Token Approvals Actually Work?
- How Are Approvals Abused? Attack Types and Real Losses
- How Do You Check Your Token Approvals?
- Should You Revoke or Just Limit an Approval?
- What Does a Good Approval Hygiene Routine Look Like?
- What Actually Matters Most in Approval Security?
- Frequently Asked Questions
- Sources
How Do Token Approvals Actually Work?
Every ERC20 token contract has an approve() function. Call it, and you're telling the contract "spender X can move up to Y of my tokens." The spender, usually a DEX or lending protocol, then calls transferFrom() whenever it needs to move funds on your behalf. NFTs use a related mechanism called setApprovalForAll, which hands a spender control over your entire collection under one contract, not just one token.
Here's the pattern in practice:
- You approve a contract for a specific token and amount (or "unlimited").
- The contract stores that allowance on-chain, tied to your address and its own.
- The spender calls
transferFrom()later, no second signature required, as long as the allowance covers it.
Most dApps default to requesting unlimited allowances because it saves you from approving again on every trade. That convenience is why unlimited approvals became the industry default rather than an edge case.
Newer standards change the shape of the risk. EIP-2612's permit function lets you approve a spender by signing a message off-chain, no gas, no transaction. Permit2 extends this further across tokens that don't natively support it. The upside is speed and lower fees. The downside: the attack no longer needs you to send a transaction at all. It just needs your signature.
How Are Approvals Abused? Attack Types and Real Losses
Academic researchers have a name for the core exploit: Approved Controllable TransferFrom, or ACT. It happens when an attacker gains control of a contract you've already approved, then uses your standing allowance to move funds without ever touching your wallet directly.
The scale is bigger than most users assume.
An academic analysis of Ethereum's approve-transferFrom ecosystem identified over 32,000 potentially vulnerable contracts and estimated losses exceeding $65 million tied specifically to ACT-class vulnerabilities.
Signature-based phishing has become a favorite attack path precisely because it skips the on-chain approval transaction that might otherwise trigger a wallet warning. A malicious site prompts you to "sign to continue," and that signature grants an allowance through a permit flow rather than a visible transaction. Security researchers point to this shift as one of the fastest-growing vectors in the space.
Badger DAO's 2021 exploit remains the reference case: attackers injected malicious scripts that tricked users into approving withdrawals, draining tens of millions before anyone noticed. The lesson wasn't a broken smart contract. It was standing approvals nobody was watching.

How Do You Check Your Token Approvals?
You don't need to guess which contracts hold access to your wallet. The tools already exist, and checking takes a few minutes.
- Open your wallet's approval view. MetaMask Portfolio includes a built-in checker that lists active allowances by token and spender.
- Cross-check with a block explorer's approval tool. Etherscan and Blockscout's revoke interface both surface approvals tied to your address, often with more detail than a wallet UI shows.
- Read the raw event if you want certainty. Every approval emits an Approval log with three fields: owner (you), spender (the contract), and value (the allowance amount). A value near the maximum uint256 number means unlimited.
- Repeat this across every chain you've used. An approval on Polygon doesn't show up when you're checking Ethereum mainnet, and the same logic applies to a Solana EVM bridge you tried once and forgot about.
Pro Tip: Bookmark your wallet address on a block explorer and check it monthly, the same way you'd check a bank statement. It takes less time than you'd think, and it's the only way to catch an allowance you don't remember granting.
Should You Revoke or Just Limit an Approval?
You have two real options once you spot a risky allowance: revoke it entirely by setting the value to zero, or overwrite it with a smaller, capped amount. Revoking is cleaner for anything you don't actively use. Capping makes sense for a dApp you trade on weekly, where you want future access without leaving an unlimited number sitting exposed.
Either action costs gas, because you're sending a new transaction that changes on-chain state. There's no way around that fee, and on a congested network it can briefly cost more than the swap that created the approval in the first place.
- Connect your wallet to an approval checker like MetaMask's or Blockscout's revoke tool.
- Identify the spender contract tied to the allowance you want to change.
- Submit the revoke (or reduced) transaction and confirm it in your wallet.
- Verify on a block explorer that the allowance now reads zero or the new capped value.
If a revocation fails or the interface won't load the transaction, overwrite the allowance with a minimal, near-zero cap instead of leaving it unlimited. In cases where a wallet is already compromised beyond approvals, moving remaining funds to a new wallet is safer than continuing to interact with the old one.
Pro Tip: Revoke approvals right after you finish using a dApp for a one-time task, like a token swap or a bridge deposit, rather than waiting for a monthly audit to catch it.
What Does a Good Approval Hygiene Routine Look Like?
Treat this like changing the locks after you lend someone a key. A short, repeated routine beats a one-time cleanup.
- Run a full approval check monthly across every chain and wallet you use.
- Use a separate, disposable hot wallet for unfamiliar or experimental dApps, keeping your main holdings isolated.
- Choose a limited allowance over unlimited whenever the dApp's interface allows it.
- Treat any unfamiliar spender address, or a contract with upgradeable admin rights, as a reason to revoke first and investigate later.
- If you haven't touched a dApp in over a month, revoke its approval. You can always grant it again in seconds.
| Habit | Why it matters |
|---|---|
| Monthly audit | Catches allowances you forgot about before they become someone else's opportunity. |
| Disposable wallets for new dApps | Limits exposure to a small balance instead of your full portfolio. |
| Prefer capped allowances | Reduces the damage ceiling if a contract is later compromised. |
How OmniRout Fits Into Safer Approval Habits
- Non-custodial by design: you hold your keys at every step, never OmniRout.
- Route comparison across 30+ chains shows fees, gas, and slippage upfront, which cuts down on repeated trial swaps and the duplicate approvals they generate.
- Transparent routing means fewer redundant transactions eating into your allowance list over time.
What Actually Matters Most in Approval Security?
Most guides treat approval hygiene as a one-time chore: revoke a few old permissions, feel better, move on. That misses the real pattern. The USENIX research on ACT vulnerabilities makes clear this is a systemic, ongoing exposure, not a rare edge case. Tens of thousands of contracts carry this risk right now, and new ones join that list every time a popular protocol gets forked or upgraded.
The conventional advice, "just don't click suspicious links," undersells the newer threat entirely. Permit-based phishing doesn't need a suspicious link. It needs a signature request that looks identical to a hundred legitimate ones you've already approved. That's the gap most casual security advice hasn't caught up to yet.
If you take one thing from this, prioritize the monthly audit over any single dramatic cleanup. Frequent traders in particular accumulate approvals fast, and a platform that shows routing and fees clearly, rather than obscuring them, naturally produces fewer of them to manage.
A Practical Next Step for Frequent Traders
If you're swapping across chains regularly, every extra approval is another line item to audit later. OmniRout is built as a non-custodial DEX and bridge aggregator, so your keys never leave your control, and its route comparison shows fees, gas costs, and slippage across 30+ chains before you commit to a swap.

That upfront visibility means fewer blind trial-and-error trades, and fewer trial-and-error trades means fewer approvals sitting around for you to track months from now. Instead of guessing which route is cheapest and approving three different contracts to find out, you compare routes first and approve once with a clearer picture of what you're signing. Compare a swap on OmniRout before your next cross-chain trade and see the fee breakdown before you approve anything.
Frequently Asked Questions
What's the difference between an approval and a swap? An approval grants a contract permission to move your tokens later. A swap is the actual trade. You often need to approve a token before a DEX can execute the swap, which is why a single trade sometimes triggers two separate transactions.
Is it safe to leave old approvals in place if I trust the dApp? Trusting the dApp today doesn't protect you if its contract is upgraded, its admin keys are compromised, or a dependency it relies on gets exploited. Reviewing token approval risks on dApps you rarely use is safer than assuming past trust still applies.
Does revoking an approval cost the same as making a swap? Gas costs vary by network congestion, not by transaction type, so a revocation can cost more or less than a swap depending on when you send it. It's still cheaper than the potential loss from an exploited unlimited allowance.

Can I check approvals across every blockchain in one place? Not universally. You typically need to check each chain separately using that chain's block explorer or a wallet's multi-chain approval view, since an allowance on one network has no bearing on another.
Sources
- How to revoke smart contract allowances/token approvals | MetaMask Help Center
- How to Revoke Unlimited Token Approvals & Dapp Permissions | Blockscout blog
- Approve Once, Regret Forever: On the Exploitation of Ethereum’s Approve-TransferFrom Ecosystem (USENIX paper)
- Token approval attack surface (TryEthernal blog)
