A token approval is permission you grant a smart contract to spend tokens from your wallet on your behalf. The amount it may spend is called the allowance. Every decentralized exchange and DeFi protocol works through approvals, and so do most wallet drainers. Permit-based approval attacks accounted for 38% of losses among phishing incidents over $1 million in 2025, according to Scam Sniffer.
Why token approvals exist
A smart contract cannot reach into your wallet on its own, no matter how it is written or who deployed it, because the token standard does not permit it without your signature. You have to authorize it.
To swap tokens on a decentralized exchange, the exchange contract needs to move your tokens from your wallet into the pool. Before it can, you sign a transaction granting it permission to do so. That permission is the approval.
The design is sensible. No contract can touch your tokens without explicit consent. The problem is what "consent" looks like in practice, and how long it lasts.
How a token approval works
Three steps, and the middle one is where losses happen.
- You visit a site that needs to move your tokens, such as a decentralized exchange.
- Your wallet asks you to sign an approval, specifying which token, which contract, and how much.
- The contract can now move up to that amount whenever it chooses, until the approval is revoked or used up.
Most people never think about step three. Closing the site does not expire the approval. On the blockchain, it persists indefinitely.
Limited vs unlimited approvals
| Limited approval | Unlimited approval | |
|---|---|---|
| Amount authorized | Exactly what the transaction needs | Effectively infinite |
| Gas cost | New approval per transaction | One approval, reused |
| Risk if contract is compromised | Only the approved amount | Your entire balance of that token |
| Default on many sites | No | Yes |
Because it saves users a transaction fee on every subsequent trade, sites default to unlimited. Drainers exploit that convenience. Granted to a legitimate contract in 2023, an unlimited approval is still live in 2026, and if that contract is later exploited, the attacker inherits your permission.
Permit signatures, the newer version
Because they are transactions, standard approvals cost gas. Introduced through standards like EIP-2612, Permit signatures let you grant an approval by signing a message off-chain, for free.
Convenient for users. More so for attackers.
A Permit signature can be presented as almost anything: a login, a claim, a verification step. You see a signature request rather than a transaction, no gas is charged, and nothing visibly happens. On-chain, the attacker then submits the signed permission and drains the approved tokens.
The largest single phishing theft of 2025, $6.5 million in September, used a malicious Permit signature. After Ethereum's Pectra upgrade in May 2025, attackers added variants exploiting the new EIP-7702 account abstraction feature.
How drainers use approvals
Across thousands of incidents, the sequence is consistent.
- A fake site, fake airdrop, or fake support account gets you to connect a wallet.
- It presents an approval or Permit request disguised as something routine.
- You sign.
- Nothing happens immediately, which is why victims often do not realize.
- Days or weeks later, the drainer contract calls the approval and empties the token.
Scam Sniffer recorded 106,106 wallets drained through phishing in 2025. Most involved a signature the victim actively provided.
How to protect your wallet from malicious approvals
- Read the approval. Wallets increasingly show which token, which contract, and how much. If a site you expected to log into is requesting spending permission, stop.
- Set limited amounts where the interface allows, accepting the extra gas.
- Revoke stale approvals periodically using a revocation tool. Any approval you do not remember granting should go.
- Treat Permit requests as approvals. They are, regardless of what the site calls them.
- Never sign anything from a site you reached through a link in a message.
- Use separate wallets. One for interacting with new or untested sites, holding only what you are willing to lose. Another for long-term holdings that never connects to anything.
What approvals do not do
- They do not move funds by themselves. The contract has to act on them. A malicious contract will. A legitimate one moves only what your transaction requires.
- They do not expire. Unless revoked, they persist.
- They do not apply to your native coin. ETH, SOL, and other native assets do not use the approval mechanism. Tokens do.
- They are not reversed by restoring your wallet. A seed phrase restore brings back your keys with every approval still attached.
Where mb.io fits
On-chain interaction is where approvals live. Inside a regulated exchange, trading never triggers one, because trades settle in the platform's own ledger.
mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.
- Regulated by VARA in the UAE and AUSTRAC in Australia
- Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
- 10/10 security score from Hacken, an independent blockchain security auditor
- Withdrawal controls that let you verify a destination before funds move
- Buy, sell, and swap in three steps, from sign-up to purchase
- 24/7 multilingual client support
Open your account and start trading on mb.io.
Frequently asked questions
What is a token approval?
Permission granted to a smart contract to spend tokens from your wallet, up to a specified amount called the allowance. Every decentralized exchange requires one before it can move your tokens.
Why are unlimited approvals dangerous?
Authorizing a contract to move your entire balance of a token, they persist until revoked. If that contract is later exploited, or was malicious from the start, the attacker inherits the permission.
What is a Permit signature?
An approval granted by signing a message off-chain rather than sending a transaction. Free and convenient, and easy to disguise as a login or claim. Permit-based attacks caused 38% of large phishing losses in 2025.
How do I revoke a token approval?
Using a revocation tool, which lists every approval attached to your address and lets you cancel them. Each revocation is a transaction and costs gas.
Do token approvals expire?
No. Until revoked or used up, they remain active. Granted years ago, an approval is still live unless you canceled it.
Does restoring my wallet remove old approvals?
No. Approvals are recorded on the blockchain against your address, not in your wallet software. Restoring the wallet restores the keys with every approval intact.
Why did nothing happen when I signed a malicious approval?
Because the approval itself moves nothing. Later, often days or weeks afterwards, the attacker's contract acts on it, which is why victims frequently do not connect the signature to the loss.
Do I need approvals to trade on an exchange?
Not on a centralised one. Trades settle in the platform's internal ledger without touching the blockchain, so no smart contract approval is involved.

