A token approval gives a spender address permission to move an ERC-20 token from a wallet. The permission sits in the token contract, so closing a tab or disconnecting a wallet does not remove it. A user can finish a swap and still leave an allowance behind for the router that handled the trade.
The ERC-20 standard separates permission from movement. approve sets how much a spender may withdraw, allowance reports the remaining amount, and transferFrom moves tokens after the owner has authorized the caller. An approval therefore changes the spending ceiling; it does not prove that a transfer occurred.
Why the amount matters
An exact approval limits the spender to the amount entered. A larger allowance can support later transactions without another approval, but unused capacity remains available. An effectively unlimited approval can cover tokens received long after the first interaction, as long as the permission remains in force.
That trade-off is operational, not cosmetic. Repeated approvals cost gas and add another transaction, while broad approvals expose more of the token balance if the spender contract, its upgrade controls, or the interface directing the user is compromised. The relevant identifiers are the chain, token contract, wallet and spender address. A familiar token ticker or application name does not identify all four.
Signed permits can also create allowances
ERC-2612 adds a permit function that sets an allowance from a signed message. The signed data includes the owner, spender, value, nonce and deadline. When the contract accepts a valid signature before its deadline, it sets the allowance and increments the owner’s nonce. A wallet screen labeled as a signature request can therefore authorize token spending without presenting a conventional approve transaction first.
Permit2 adds a separate contract layer. Uniswap’s documentation describes AllowanceTransfer as a standing permission with an amount and expiration, while SignatureTransfer authorizes a nonce-scoped transfer. Permit2 still needs a standard token approval before it can move that token. Its source code stores allowances by owner, token and spender, and its one-time transfer path checks the deadline, amount and nonce before calling the token’s transferFrom.
A safer approval check
Start with the network and exact token contract. Then inspect the spender address, the allowance amount and whether the application is still in use. Reduce or revoke permissions that are obsolete or broader than necessary through a trusted wallet or block explorer, and confirm the resulting transaction on the correct chain.
Check signature-based permissions separately. A zero ERC-20 allowance may block immediate token movement, but it does not erase a signed message or Permit2’s own permission state. Permit2’s contracts include separate nonce invalidation functions for its allowance and signature-transfer paths. The correct response depends on which layer granted the authority.
A revocation only changes future authority. It cannot reverse a transfer that already succeeded. During an incident, confirm both the approval state and any transfers from the wallet rather than treating an approval event as proof that funds moved.
Adapted from Token Approvals in Crypto: Allowances, Unlimited Spending, Permit2, and How to Revoke Safely.