Buy now

Every time you have swapped a token, listed an NFT or connected to a lending app, you granted that contract permission to move a token out of your wallet. The permission does not expire, it survives you closing the tab, and on most apps the default amount it covers is unlimited. If you have been onchain for a couple of years, there are probably standing permissions in your wallet that you have entirely forgotten and that still work.

What an approval is, and why it lasts

Token standards separate holding from spending. Under the ERC-20 design, a contract cannot take your tokens on its own; you first call an approve function naming that contract and an allowance, and from then on it can move up to that amount whenever it likes. The swap you were doing needed the permission, so the wallet asked, and you confirmed.

The allowance is where this gets uncomfortable. Asking for the exact amount would mean a fresh approval and a fresh fee for every trade, so many interfaces request an effectively unlimited ceiling once and never bother you again. That convenience is worth something, and it means the permission you granted for a 200 dollar swap in 2023 covers your entire balance of that token in 2026.

Approvals are also per token and per contract, which is why they accumulate quietly. There is no dashboard in most wallets showing what is outstanding, no reminder, and no expiry. The only thing that removes one is you removing it.

Why this is worth an hour of your time

Approval phishing is a mature criminal business rather than an edge case. The scam works by getting you to sign an approval instead of stealing anything directly: a site that looks like the one you meant to visit, an airdrop claim, a support agent walking you through a fix. Nothing leaves your wallet at that moment, which is what makes it hard to notice, and the drain comes later.

Chainalysis has tracked this pattern since May 2021 and put at least 1 billion USD of cryptocurrency stolen through approval phishing over the period it studied, with a single address responsible for 44.3 million USD taken from thousands of victims. Law enforcement has started working the pattern directly: Operation Spincaster processed more than 7,000 investigative leads and addressed roughly 162 million USD in approval-phishing losses.

An old approval is also a standing dependency on a contract staying safe. Protocols get exploited, admin keys get compromised, and an allowance you granted to a project that has since been abandoned is a door you left open in a building nobody maintains any more.

How to see and remove what is outstanding

The tooling is good and the job is not difficult. Block explorers carry an approval checker: Etherscan has one for Ethereum, and the equivalent explorers cover other networks. Revoke.cash lists open approvals for an address broken down by token and contract across many chains, and it is the tool most people reach for because it presents the whole picture in one view.

Connect your wallet, or paste your address to look without connecting, and read what comes back. You are looking for unlimited allowances, contracts you do not recognise, and anything tied to a project that no longer exists. Revoking is an onchain transaction, so it costs a network fee; on Ethereum mainnet those fees have recently made a single revocation a matter of cents, and on other networks it is cheaper still.

Do this now, then put a reminder in your calendar for every few months and after any period of heavy onchain activity. Where a token balance matters to you and the approval is old, revoke first and grant a new one when you next need it.

Newer designs reduce how much this piles up. Uniswap's Permit2 replaces the pattern of approving every app with one approval to a shared contract, after which individual apps get authorised by offchain signatures that carry an expiry. Where an interface offers it, taking that route leaves less behind.

The signing problem underneath

Approvals expose something about how most people transact: you are asked to confirm a request that your software has described to you, and you are trusting that description. A compromised interface can present a swap and request an unlimited allowance to an address you never see, and a wallet that shows you a spinner and a confirm button gives you no way to catch it.

This is what blind signing means, and it is the reason Ryder One shows transaction detail on its own 1.6 inch AMOLED screen instead of relying on whatever the connected app claims to be doing. The button that approves is wired directly to the secure element, so no software path can sign without a deliberate press on the device. Reading what is in front of you is still your job; the device's contribution is making sure what you read came from the transaction rather than from the website.

Your keys are a separate question

Revoking approvals protects tokens you hold from contracts you once trusted. It does nothing for the key itself, and protecting that is the job a hardware wallet exists to do.

Most people protect it with a seed phrase on the card from the box, which leaves the position depending on paper surviving water, fire and house moves. Steel plates fix durability and keep the underlying shape of the risk, since one object still grants full access to whoever reads it.

TapSafe Recovery splits the backup so no single item carries it: the Recovery Tag holds half, your paired phone holds the other half encrypted in your own iCloud or Google Drive rather than on the handset, and the two together restore the wallet. Optional Recovery Contacts hold a quarter share each without seeing your balances. The seed phrase stays on the device as a last resort under the BIP-39 standard, so you are never locked to our hardware.

The short version

Go and look at your approvals today. Most wallets that have been used for a while are carrying permissions their owner would not grant again, and removing them costs a few cents and about an hour of attention.

Ryder One is 149 USD for the Starter Combo. Keys are generated inside an EAL6+ Infineon SLC38 secure element and never leave it, connectivity is NFC only with no Bluetooth, USB data path or Wi-Fi, and the firmware has been audited by Halborn with the full report published.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More