Approval Phishing: How Scammers Drain Wallets Through Signatures
Approval phishing tricks wallet users into signing permissions that let scammers move tokens. Learn what to check before approving any request.
Author: Damon Salvatore · Senior Content Marketer Approval phishing is one of the most important Web3 risks because the scam can look like a normal wallet prompt. Instead of stealing a password, the attacker tricks the user into granting permission.
That permission may let a malicious contract move tokens or NFTs. In some cases, the wallet balance is not drained immediately, which makes the user believe nothing happened until the attacker later uses the approval.
A good approval review starts with four fields: asset, spender, allowance, and the exact action you intended to perform.
Quick Answer: What Is Approval Phishing?
Approval phishing is a scam where a user is tricked into signing a token approval, permit, or permission request that allows a malicious spender to move assets from the wallet. The user may think they are claiming, verifying, or connecting, but the signature grants real asset-moving power.
MetaMask token approval explanation defines token approvals as permission for a DApp to access and move a specific token type from a wallet.
MetaMask malicious approval guidance and MetaMask approval revocation guide are useful for understanding why risky permissions should be revoked quickly when identified.
Key Takeaways
- A token approval is a real permission, not just a login step.
- Unlimited approvals increase damage if the approved spender is malicious.
- A signature can be dangerous even when it does not show an immediate transfer.
- Revoke unused approvals after DeFi sessions or suspicious prompts.
- Use storage wallets for storage and separate interaction wallets for high-risk DApps.
How Approval Phishing Drains Wallets
The attacker does not need your seed phrase if you give their contract permission to move assets.
A phishing page may ask for a wallet connection, then show a prompt labeled as claim, verify, mint, stake, secure, or migrate. The request can hide an approval that lets a spender move tokens.
Traditional transfers move assets immediately. Approvals are different: they grant permission that can be used later. This delay makes approval phishing confusing because the user may not see an instant loss.
Permit-style signatures and batch transactions can make prompts harder to read. The safer default is to reject unclear permissions and verify the contract through a trusted source.
| Signal | Safer response |
|---|---|
| Unlimited token approval | Avoid unless the DApp is trusted and the use case requires it. |
| Unknown spender address | Reject until the contract is verified from official docs. |
| Signature with vague text | Reject and research the request before trying again. |
| Unexpected NFT approval | Assume it can transfer collection assets until proven otherwise. |
| Prompt appears after a support link | Close it; support should not require broad wallet permissions. |
How to Review Approvals Before Signing
Ask what the permission allows, who receives it, and whether the amount is limited.
Before approving, identify the token, spender contract, allowance size, and action you are trying to perform. If the prompt does not explain those fields clearly, stop.
For high-value wallets, avoid routine DeFi approvals altogether. Use a smaller interaction wallet, limit allowances where possible, and revoke unused approvals after the session.
Do not confuse wallet connection with token approval. Connecting a wallet lets a site see public address information. Approving a token can give a contract permission to move assets.
Approval Phishing Prevention Checklist
- Identify the token or NFT being approved before you sign.
- Check the spender contract and compare it with official DApp documentation when possible.
- Avoid unlimited approvals for wallets that hold meaningful balances.
- Reject vague signatures that do not match the action you are trying to perform.
- Use a smaller interaction wallet for DeFi, mints, and experimental DApps.
- Review and revoke old approvals after high-risk sessions or suspicious prompts.
What to Do After a Suspicious Approval
If you catch the approval before assets move, use a trusted approval management path such as Revoke.cash or wallet-native approval tools to revoke or reduce permissions.
If assets already moved, save transaction hashes, approved spender addresses, malicious URLs, and screenshots. Do not send more gas to the wallet if a sweeper bot appears to be draining it immediately.
If your seed phrase or private key was entered anywhere, revoking approvals is not enough. Move remaining assets to a new wallet created from a clean setup.
Where UKey Fits
UKey adds a signing boundary; it does not bless every approval.
UKey Core 26 can make approval review harder to skip because signing happens on a dedicated device. The user still has to understand the permission being approved.
For UKey storage wallets, keep routine DApp approvals away from long-term holdings. A hardware wallet is strongest when paired with wallet separation and approval hygiene.
Related Resources
Continue with these UKey guides to connect this threat model with safer wallet setup, approvals, and self-custody habits.
- How to Secure Your Crypto Assets
- Why a Hardware Wallet Needs a Screen
- How to Revoke Token Approvals
- DeFi Token Approval Safety
- Address Poisoning Attacks
- Crypto Wallet Drainers
- Fake Wallet Apps
This article is for educational purposes only. It is not financial, legal, tax, cybersecurity incident-response, or investment advice. Threats, wallet interfaces, and supported security features can change. Always verify official sources and current wallet instructions before signing transactions or moving funds.