Some of the most painful crypto losses happen to people who did everything they were told — never shared a seed phrase, never typed it into a website. Their wallets drained anyway. The culprit is usually a quieter trap called approval phishing, and it's worth understanding before it happens to you.
First, what a "token approval" is
When you use a real DeFi app — a decentralized exchange, a lending platform — you often have to grant it permission to move a specific token on your behalf. This is a normal, necessary step called a token approval. You sign it in your wallet, and from then on that app can move that token without asking each time.
This exists for convenience. The problem is that an approval can be written far more broadly than you realize — including permission to move all of a token, with no expiry.
How the scam works
Approval phishing turns that normal mechanic against you:
- You land on a fake or malicious site — a phony airdrop, a "claim your reward" page, a cloned version of a real app.
- It asks you to connect your wallet and sign what looks like a routine transaction.
- What you're actually signing is an unlimited approval handing the attacker permission to move your tokens.
- Nothing happens immediately, so it feels fine. Then, minutes or weeks later, they drain the approved tokens in one transaction.
Notice what didn't happen: you never revealed your seed phrase. You "only" signed an approval. That's why victims are so often baffled — the standard advice about never sharing your phrase was followed perfectly, and it wasn't enough.
How to protect yourself
A handful of habits shut this down:
- Read what you're signing. Wallets increasingly show when a request grants spending permission. If a simple action asks to access your tokens, stop.
- Be suspicious of "claim" and "reward" pages. Unexpected airdrops and surprise rewards are the number-one bait.
- Set spending limits when you can. Some wallets let you approve only the exact amount you're transacting rather than "unlimited."
- Use a separate wallet for experiments. Keep your main holdings in a wallet that never touches unfamiliar sites.
- Revoke old approvals. Reputable approval-checker tools let you review and cancel permissions you've granted. Doing this periodically closes forgotten doors.
The takeaway
Protecting your seed phrase is necessary but not sufficient. Approvals are a second set of keys, and approval phishing is how careful people still lose funds. Treat every "connect wallet and sign" request on an unfamiliar site as a decision, not a formality — and review and revoke your approvals from time to time.
If a deal feels urgent, free, or too generous, that urgency is the scam doing its job. Close the tab.