Key points
- An approval can authorize a smart contract to move tokens.
- The approved amount and contract address matter.
- Old approvals can remain active after you stop using an app.
- Review and revoke permissions as part of wallet hygiene.
Signing is not always sending
On token networks, one transaction can grant a contract permission to transfer a token later. The approval may be limited to a specific amount or can be very broad. Users who focus only on the immediate swap can miss the long-lived permission.
Read the transaction type and contract address in the wallet before signing. A familiar website can still route to an unexpected contract if the site or device is compromised.
Limit persistent exposure
Prefer smaller or purpose-specific approvals where the interface supports them. Use separate wallets for different risk levels when that fits your workflow, and review permissions after experimental DeFi use.
Revocation itself is an on-chain transaction and can require network fees, so plan for it before you need it urgently.
Compare wallet tooling honestly
Some wallets surface approval details, simulation or risk warnings more clearly than others. These features can improve decision context, but they do not guarantee that a contract is safe.
A wallet comparison should describe the protection feature and its scope rather than converting it into a blanket security score.
Primary reading
These official sources provide background for the risk and custody concepts used in this guide. Product-specific facts should still be checked against the relevant operator and jurisdiction.