Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › Revoking token approvals

How to revoke token approvals

By Yair Revach · Co-founder, Chain Pursuit · 8 min · Last updated 1 October 2026

A token approval lets a smart contract move a specific token from your wallet, later, without asking again. Many default to unlimited. Revoking withdraws that permission, and it costs a small transaction fee on each chain. What it cannot do is return anything already taken, or help at all if your recovery phrase was exposed.

Do this first if funds are moving

Revoking is the second step, not the first.

If tokens are leaving your wallet right now, move what remains to a new wallet before you revoke anything. Revocation is a transaction that takes time to confirm, and an attacker with a live approval can act during that window. Our guide to a compromised wallet covers the order and why it matters.

If your recovery phrase may have been exposed, revoking achieves nothing at all. The phrase is the wallet, and the attacker can recreate it anywhere.

What an approval is

Most tokens work through a permission system. Before a decentralised application can move a token on your behalf, to swap it, stake it, bridge it or list it, you grant that application permission.

This is normal and necessary. It is also where the risk sits, because of two properties people rarely notice.

Approvals are usually unlimited by default. Many interfaces request permission to move any amount of that token, rather than the amount you are about to trade. It saves you approving again next time, and it means the permission covers your entire balance.

Approvals persist until revoked. There is no expiry. An approval granted in 2022 to a protocol that no longer exists is still live today, and whoever controls that contract can still use it.

Together those explain the delay people find confusing: you approve something, nothing happens, and weeks later the wallet empties. Our wallet drainer guide covers that mechanism in full.

Approvals, signatures and Permit

Not all permissions look the same, and the most dangerous ones are the least visible.

What you grantedGas costAppears in your history
Standard approvalYesYes, as a transaction
Permit signatureNoneNo
Permit2NoneNo
EIP-7702 delegationVariesPartially

A standard approval is an on-chain transaction. It costs gas, shows in your history, and revocation tools can see it.

A Permit signature grants the same kind of permission by signature alone. No gas, no transaction, nothing in your history at the moment you sign. Scam Sniffer found Permit and Permit2 accounted for 38% of losses above $1 million in 2025, and the largest single incident that year, around $6.5 million in September, came from one malicious Permit signature.

This matters for revocation. Because a Permit leaves no on-chain record when signed, a revocation tool may not list it the way it lists a standard approval. Checking your approvals is worth doing, and it is not a complete picture of what you have authorised.

Where to check

Use an established tool, and navigate there by typing the address. Fake revocation sites exist and are themselves drainers, which is a particularly cruel design: they target people who already suspect something is wrong.

Revoke.cash covers many chains and shows approvals grouped by token with the amount authorised.

Etherscan's Token Approval Checker, and the equivalent on BscScan, Polygonscan and Arbiscan, is run by the block explorer for that chain.

Your wallet may also have this built in. Rabby shows approvals natively. Check your wallet's settings before reaching for a third-party tool.

Connecting a wallet to review approvals is read-only. You are not authorising anything by looking.

How to revoke

  1. Open the tool by typing its address. Not from a search advertisement, not from a link someone sent you.
  2. Connect your wallet. Reviewing costs nothing.
  3. Select the chain. Approvals are per-chain and the tool shows one at a time.
  4. Look for two things: contracts you do not recognise, and anything marked unlimited.
  5. Revoke. Each revocation is a transaction and costs gas.
  6. Repeat on every chain you have used.

That last step is the one people miss. Revoking on Ethereum does nothing on BNB Chain, Polygon, Arbitrum, Base or Optimism. If you have used the same address across several networks, each needs checking separately.

What to revoke, and what to leave

Revoking everything is safe but costs gas, and you will re-approve the things you use.

Revoke without hesitating: anything you do not recognise, any unlimited approval to a contract you used once, anything connected to a site that no longer exists, and everything on a wallet you suspect was compromised.

Reasonable to keep: capped approvals to protocols you use weekly, where the amount is close to what you trade.

Cap rather than revoke, where the tool offers it: some interfaces let you reduce an unlimited approval to a specific amount instead of removing it. That keeps the convenience and bounds the exposure.

Gas costs

Each revocation is a transaction, so cost depends on the chain and the moment.

On Ethereum during busy periods, revoking a dozen approvals can cost more than the tokens are worth. On most other chains it is trivial.

If the cost is prohibitive: the alternative is moving your assets to a fresh wallet, which leaves the old approvals live but irrelevant, since the wallet they apply to is empty. For a badly compromised address this is usually the better move anyway.

Do not send gas to a compromised wallet to fund a revocation. Automated sweeping takes it, often within one block.

How often

Quarterly is a reasonable rhythm for an active wallet, plus immediately after using anything unfamiliar.

The stronger habit is structural rather than scheduled: keep long-term holdings in a wallet that never connects to applications, and let the wallet that does connect hold only what you can afford to lose. Our warm wallet guide covers running two.

What revoking does not do

Worth being direct, because people reach for revocation expecting more than it offers.

It does not recover anything. Tokens already moved are gone. Revocation is preventive only.

It does not help if your recovery phrase was exposed. The attacker holds the wallet itself.

It does not undo a Permit you have already signed if the permission was exercised before you checked.

It does not make a compromised wallet safe to reuse. If you are revoking because something went wrong, create a new wallet.

Red flags

Checklist

What this guide cannot do

Revoking reduces exposure. It does not make a wallet safe, and it cannot see every permission you may have granted, particularly gasless signatures. Nothing here guarantees that funds cannot be taken.

This is general information, not legal or financial advice.

If something has already gone, our evidence checklist covers what to preserve, and the country guides explain where to report it. Expect an approach afterwards from someone offering recovery: read how to spot a recovery scam before replying.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

Scam Sniffer, 2025: Crypto Phishing Losses Fall 83% to $84 Million, January 2026. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/

Scam Sniffer figures reflect that firm's observed EVM wallet-drainer dataset and are not a complete total across all blockchains.

Frequently asked questions

Does revoking a token approval cost money?

Yes. Each revocation is an on-chain transaction and costs gas on that network. On Ethereum during busy periods a batch of revocations can cost more than the tokens are worth; on most other chains it is negligible. Moving assets to a new wallet is sometimes cheaper.

Will revoking approvals get my stolen tokens back?

No. Revocation is preventive. It stops future transfers using that permission and does nothing about anything already moved. Revoke anyway, immediately, to prevent further loss.

Do I need to revoke on every blockchain separately?

Yes. Approvals are specific to each network. If you have used the same address on Ethereum, BNB Chain, Polygon, Arbitrum, Base or others, each must be checked and revoked separately.

Is it safe to connect my wallet to a revocation tool?

To an established one reached by typing the address, yes. Reviewing approvals is read-only. Fake revocation sites exist and are themselves drainers, so never reach one through an advertisement, a search result you did not verify, or a link someone sent you.

What is the difference between an approval and a Permit signature?

A standard approval is an on-chain transaction that costs gas and appears in your history. A Permit grants similar permission by signature alone, with no gas and no transaction, so nothing appears in your history at the moment you sign. That invisibility is why attackers favour it.

How often should I review my approvals?

Quarterly for an active wallet, plus immediately after using anything unfamiliar. The better habit is keeping long-term holdings in a wallet that never connects to applications at all.

I revoked everything and tokens still left my wallet. What happened?

Most likely your recovery phrase or private key was exposed rather than an approval being exploited. In that case the attacker controls the wallet itself and revocation is irrelevant. Move everything to a newly created wallet immediately.

Can I set an approval to a limited amount instead of unlimited?

Some interfaces allow it, and where offered it is worth doing. A capped approval covers the trade you are making rather than your entire balance, which bounds what a compromised contract can take.

Not sure whether something has already gone wrong?

Eleven questions showing which documentation and reporting steps are available in your case.

Check my case

Keep reading