BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Crypto Lexicon

Token Approvals and Wallet Drainers

A drainer collects standing permissions rather than seed phrases. How approvals, permit signatures and revocation actually work, and why disconnecting does nothing.

Approval and Transfer Are Two Different Acts

The ERC-20 standard separates owning tokens from being allowed to spend them. You call approve to record an allowance for a spender, and that spender later calls transferFrom to draw against it. The allowance then sits in the token contract until something changes it, patiently, indefinitely.

Grant one to a hostile contract and you have signed a blank cheque with no expiry date. For NFTs the equivalent is blunter still: setApprovalForAll hands an operator authority over everything you hold in that collection.

The Signature That Costs No Gas

ERC-2612 added permit, which lets an allowance be set by a signed message instead of a transaction. Uniswap's Permit2 extends the idea, holding time bound allowances inside its own contract once you have approved it for a token.

This is the bit that catches careful people, and it catches a lot of them. A signature request opens no gas prompt and creates no pending transaction, so it feels like showing ID rather than handing over keys. It is the authorisation. The attacker pays the gas and submits your signature for you, which is almost thoughtful of them. The absence of a fee is the attack's main selling point, not a safety feature.

Why a Drain Completes in One Block

Once permission exists, the draining transaction is entirely ordinary. There is no window to out race it, no confirmation to refuse, and no need for anyone to know your recovery phrase.

This is also why "I disconnected the site" is not a remedy. Disconnecting ends a session in your browser. The allowance is a record in the token contract, and it neither knows nor cares whether that tab is still open.

How Revocation Actually Works

Revoking means setting the allowance back to zero, and because that is a write to the chain it is a real transaction that costs real gas, as MetaMask's own guidance spells out. Tools such as Etherscan's approval checker will show you what a given address has handed out over the years, which is a sobering afternoon for most people.

The practical rule: audit your approvals periodically rather than forensically after an incident. And be sceptical of the popular advice to use increaseAllowance instead of approve: it was never part of ERC-20 and was removed from OpenZeppelin's contracts in version 5.0, so it is not the safety measure the internet still insists it is.

Knowledge check

Three quick questions on this entry. Pick an answer to see whether it is right.

Question 1 of 3Which description matches Token Approvals and Wallet Drainers?

Question 2 of 3Why can a drainer empty a wallet whose owner never shared a recovery phrase?

Question 3 of 3Which of these also belongs to Wallets & Security?

Frequently asked question

What is Token Approvals and Wallet Drainers?

A drainer collects standing permissions rather than seed phrases. How approvals, permit signatures and revocation actually work, and why disconnecting does nothing.

The Letter

One clear letter, every week.

Plain analysis of crypto infrastructure, markets and security. No price calls, no referral links, no hype.

Unsubscribe at any time. Read the privacy notice.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →