TxSonar

What did I approve, and is my wallet at risk?

An approval does not move anything. It records that a particular contract is allowed to move a particular token out of your wallet later, up to a limit. That is why the transaction shows a fee and no transfer.

Every swap on every decentralised exchange needs one, so having approvals is normal and not in itself a sign of anything wrong. What matters is which contract, and how much.

See exactly what that transaction approved

The check names the token, the contract you granted permission to, and whether the amount was unlimited. It is read-only — nothing is connected and nothing is signed.

Check your transaction

Why wallets ask for “unlimited”

Approving an exact amount means paying gas for a new approval before every trade, so most interfaces default to the maximum possible number. It is convenience, not malice, and the large established routers are approved this way by millions of people.

The cost of that convenience is real, though: an unlimited approval stays valid forever, for any amount you ever hold of that token, until you revoke it. If that contract is later compromised — or was written to be — the permission is already granted.

When an approval is the actual attack

Most drained wallets are drained through an approval, not through a stolen seed phrase. The pattern: a site asks you to “connect and verify”, “claim”, “migrate” or “sync”, the prompt looks like every other approval you have signed, and the contract it names is the attacker's. Nothing happens at the time. The tokens leave hours or weeks later.

So the question to answer is not “did money move” but what contract did I authorise, and for how much. Both are in the transaction, and the check prints them.

How to revoke one

Revoking sets the allowance back to zero. It is an ordinary transaction from your own wallet, it costs gas, and it can be done at any time — including after tokens have already been taken, which stops it happening again with what remains.

Every major block explorer runs a token-approval page for its own chain, and that is the safest place to do it: you are already on the explorer, and it is not a site that found you. We deliberately do not link a revocation tool from here — sending someone who has just been drained to a third-party contract page is how the second theft happens.

Search for the approval checker on the explorer for your network — Etherscan, BscScan, Arbiscan, Solscan, Tronscan — and reach it by typing the explorer's address yourself.

What revoking cannot do

  • It does not bring back tokens already moved. Those transfers are confirmed and cannot be reversed by anyone.
  • It does not help if the seed phrase itself was exposed. In that case the wallet is entirely under someone else's control, revoking changes nothing, and the only answer is a new wallet with a new phrase.

And to be blunt about the aftermath: anyone who contacts you offering to reverse a drain for a fee is describing something impossible. How to tell.

Tokens that arrived on their own

Unfamiliar tokens appearing in a wallet are unsolicited and cost nothing to ignore. Holding one is harmless; interacting with it is not — the usual purpose is to route you to a site that asks for an approval. Leave them alone and they are inert forever.

Data version 9. This page describes how approvals work, which does not change with an exchange's policy.

If that was not your case

If the transfer reached an exchange and was never credited, the answer depends on that exchange's own rules: what each exchange does about it.

No wallet connection. No seed phrase. Read-only — we never ask for one, and no legitimate service ever will.