On each network, inspect approved spenders, token and limit. Revoke permissions you no longer need with a trusted tool, then verify the confirmed transaction. If a recovery phrase is exposed, revocation alone is insufficient.
Token, spender and limit
Disconnect versus revoke
Use a trusted source
Identify the approval
An ERC-20 approval lets an address or contract spend a token up to a set limit. Check the network, token contract, spender and allowance; an unlimited amount increases exposure.
Separate the actions
Disconnecting a site ends an interface session but generally does not remove an on-chain approval. A message signature or off-chain permission may follow different rules: read every request before signing.
Review access
Open the wallet’s own tool or a known block explorer yourself, select the correct network and compare addresses with actual activity. Avoid messages claiming you must urgently follow a revocation link.
Revoke carefully
Reduce or cancel an approval you no longer need. Revocation is normally an on-chain transaction and may require the network’s native asset for fees. Read the wallet prompt before signing and wait for confirmation.
Verify afterwards
Refresh the approval list after confirmation. Revocation cannot recover assets already moved and cannot secure a compromised key or recovery phrase; that calls for a migration plan from a clean device.
Verify a revocation result
Closing a wallet session does not cancel onchain allowances. Revocation is a transaction on the right network, requires fees and must be confirmed before it is effective.
- Check contract, spender and limit in an explorer.
- An exposed phrase requires a new key; revocation cannot repair that secret.
Practical case: decision and limits
Revoking a spender may leave an earlier offchain signature relevant, depending on type, nonce and expiry. Distinguish recorded allowance, signed permit and NFT operator approval; one list may not cover every mechanism. Confirm revocation on the correct chain and contract. If keys are compromised, reducing allowance does not prevent fresh thief-signed operations.
A concrete verification
Read spender and allowance after confirmation: disconnecting a site does not erase on-chain permission.
Checks to make
| Topic | Check |
|---|---|
| Identify the approval | Token, spender and limit |
| Separate the actions | Disconnect versus revoke |
| Review access | Use a trusted source |
| Revoke carefully | Confirm the transaction |
| Verify afterwards | Assess remaining risk |
Frequently asked questions
Is disconnecting my wallet enough?
No. An on-chain token approval can remain active after a site is disconnected.
Does revoking close a DeFi position?
Generally the spending permission changes, while an existing position is separate. Check the specific protocol.
Why does revocation cost a fee?
Changing the approval is an on-chain transaction and normally needs the network’s native asset for fees.
Does ERC-20 allowance permit spending native ETH?
It covers the token managed by that contract, not native ETH automatically. Transactions, account delegation or other permissions can have broader effects. Identify the exact request; an allowance list does not summarize every granted power.
Verifiable sources
Independent educational content reviewed against primary documentation. No personalized recommendation or promise of returns. Updated October 6, 2026



