Open app

NexFlow › Token approval scams

Token approval scams — the allowance that keeps stealing

An approval scam doesn't take anything when you sign it — it takes the right to take, whenever it wants, forever. The mechanics, the dormant-drain pattern, and the audit-and-revoke defense.

Updated 2026-10-06 · ~8 min read · every claim sourced and dated

The approval scam is the most elegant theft in crypto because it doesn’t look like theft at the time: no funds move when you sign, nothing alerts, and the wallet reads “transaction succeeded”. Weeks later the balance is gone and the victim can’t connect the empty wallet to the harmless-looking click. The mechanics are worth knowing precisely because the danger window is invisible.

Every claim below names its source and date.

What an approval actually is

An ERC-20/SPL token approval is a standing permission recorded on-chain: “contract X may move up to N of my token Y, whenever it calls, for as long as the approval stands.” Legitimate dapps need this — a DEX can’t swap your tokens without an allowance. The scam weaponizes the same primitive: get the victim to approve an attacker-controlled contract, for an unlimited amount, on a token they actually hold.

Two properties make it a perfect theft vehicle. First, “unlimited” is the default UX — most interfaces ask for infinite allowance so you never approve twice, and victims click through it as routine. Second, the approval is dormant — the attacker can wait weeks before pulling, by which time the victim has forgotten the site and mentally decoupled the drain from the cause.

How the con presents itself

The lure asks for an approval in a context where it seems required: “approve to stake for rewards”, “approve to claim your airdrop”, “approve to check eligibility”, “approve to add liquidity”. The contract behind the request is attacker-controlled — verified-looking front end, unaudited back end. Sometimes the approval is requested on a token the victim holds meaningful balance in specifically because the drainer script first reads the wallet’s holdings and picks the most valuable asset to target — the scam page tailors the request to your portfolio.

The experienced-user version is the Permit/Permit2 path: instead of an on-chain approve transaction, the site asks for an off-chain signature that authorizes a transfer — the scam page says “sign to verify, gasless!” and the signature it requests is the permit payload itself. No transaction to inspect, just a signature the wallet renders as an unreadable blob.

The dormant-drain pattern

Documented approval-drainer campaigns deliberately delay the pull — hours to weeks — for two reasons: it severs the mental link between the sketchy site and the loss (victims report “hacked out of nowhere” rather than “that airdrop site drained me”), and it lets the kit harvest from victims who keep depositing into the compromised wallet. Some campaigns monitor the approval and pull only when the balance crosses a threshold — the approval is a fishing line left in the water.

The honest asterisk: the defense is routine, not heroic

Here is the part that makes this scam category infuriating rather than clever: it is entirely preventable with a habit. Legitimate DeFi does ask for approvals — the mechanic itself isn’t the red flag; the site asking is. “An approval request from a site you don’t fully trust is the attack” is the whole rule, and it works because an approval on nothing is worthless to the scammer — they need you to grant it on tokens you hold.

Audit and revoke — the two maintenance moves

The tools that make the defense mechanical: every major chain has approval-audit surfaces (revoke.cash is the best-known; explorers show token approvals per address). Audit any wallet that ever interacted with a claim/mint/airdrop page — the list shows every standing allowance per contract, and anything pointing at a contract you don’t recognize gets revoked on the spot. Revoking is a normal transaction and costs a small gas fee — the approval dies and the dormant drain dies with it.

For the Permit/Permit2 variant, the same audit tools surface off-chain-signature grants where the standard supports it — but the cleaner defense is upstream: treat any “gasless signature” request from an untrusted page the same as an approval request, because that is exactly what it is.

Why the unlimited default exists — and why that's the problem

The unlimited allowance isn't a scam invention — real DeFi interfaces default to it for a defensible reason: each approval costs gas, and approving max once is cheaper and smoother than re-approving before every swap. Uniswap-style front ends normalized the pattern, and now "infinite approval" reads as routine UX rather than a decision. That's precisely what makes it exploitable — the scam payload hides inside the click-through habit the legitimate ecosystem trained.

Wallets are slowly fixing the framing — several now render "this contract can spend your ENTIRE balance" rather than showing a raw number — but the habit is older than the warnings, and the kits ship pages that frame the approval as a routine connect step ("approve to continue") specifically to slot into the muscle memory real dapps built.

The second-order move: approvals as fingerprinting

A subtler abuse documented on both sides: the list of a wallet's standing approvals is on-chain public data, and attackers read it as a fingerprint. A wallet holding stale unlimited approvals to old, unaudited, or abandoned contracts is a wallet with open attack surface — abandoned-contract exploits (a project rugging its own contract, or a once-legitimate contract being compromised) can turn a two-year-old approval into a drain long after the victim forgot the site existed. The audit isn't only about scam grants — every standing approval is a live permission to whatever that contract is today, not what it was when you signed.

That reframes the maintenance rule: revoke isn't just "clean up after a sketchy click" — it's "reduce the set of contracts authorized to move my funds to only the ones I'd grant today." A wallet that has touched airdrop pages, defunct dapps, and long-forgotten farms accumulates attack surface silently, one routine approval at a time.

The verdict, precisely

A token approval scam is a standing permission granted under a false story — it steals the right to steal, later. The defense is two habits: never approve from a page you wouldn’t wire money through, and audit/revoke standing approvals on a schedule. The mechanic that makes DeFi composable is the same one that makes it dranable — the difference is which contracts you tell it to trust.

Frequently asked

What is a token approval scam?

Tricking you into signing an unlimited token allowance to an attacker contract — nothing moves at signing, but the contract can pull those tokens whenever it wants, weeks later.

Does an approval scam take funds immediately?

Not necessarily — documented campaigns wait days to weeks so victims can't link the drain to the site that caused it. The approval is dormant until the attacker pulls.

What does 'unlimited approval' mean?

The default allowance most dapps request — the contract may move your entire balance of that token, repeatedly, forever, until revoked. Convenient for real apps; the scam's whole payload for fake ones.

What is a Permit2 signature scam?

The gasless variant — an off-chain signature authorizing a token transfer, presented as 'sign to verify'. No transaction to inspect; the signature itself is the grant.

How do I check my open approvals?

Approval-audit tools (revoke.cash, explorer approval views) list every standing allowance per contract on your wallet — revoke anything pointing at a contract you don't recognize.

Is a signed approval reversible?

The permission is — revoke it and the dormant drain dies. Anything already pulled under the grant is a final on-chain transfer; revocation is prevention, not recovery.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product