A joint security briefing published Sept. 23 warns that wallet funds can be drained without a stolen seed phrase or private key when users have already granted a malicious or compromised smart contract permission to move their assets. The document focuses on token approvals, off-chain signatures and address poisoning, arguing that routine wallet habits can leave users exposed long after they close a website or delete an app.
On EVM-compatible networks, an ERC-20 approval is more than a one-time confirmation for a swap. It can create a standing authorization that lets an approved address or contract transfer tokens through the transferFrom function, up to the approved limit, without generating a fresh prompt for the wallet owner.
That structure can turn a small intended trade into a much larger exposure. The briefing gives the example of a user seeking to swap 100 USDC but approving an unlimited allowance instead. A malicious operator, or an attacker exploiting a vulnerability in the approved contract, could then attempt to move far more than the original 100 USDC.
Chainalysis estimated in its 2026 Crypto Crime Report that scams took about $17 billion in cryptocurrency during 2025. The figure covers a broad range of fraud, but the briefing places wallet authorization abuse among the practical threats that users can reduce through tighter control of approvals and signatures.
Approvals can outlive the app or website
The briefing stresses that on-chain permissions remain active until they are revoked on the blockchain. Uninstalling a wallet application, disconnecting from a decentralized application, changing phones or resetting passwords does not cancel an approval that has already been recorded in a smart contract.
That creates a gap between how users may perceive a wallet connection and how permissions operate technically. Connecting a wallet to a website is usually only an initial step. The later transaction or signature request determines whether the site receives authority to spend tokens, manage NFTs or use a signed authorization at a later point.
NFT owners face a related risk through setApprovalForAll, a standard function that can authorize an operator to manage every NFT held by the wallet under a particular collection contract. Unlike an approval tied to one token ID, the permission can cover an entire group of collectibles from the same contract.
The document also flags Permit and Permit2 signatures. These mechanisms allow users to sign a message off-chain rather than submit an approval transaction directly on the network. The signature does not consume gas when it is created, but it can be used later to establish or exercise token-transfer rights. That convenience can make the request appear less consequential than a conventional on-chain approval.
Users should check the target receiving the authorization, the asset involved, the amount and the breadth of the requested permission before signing, the briefing says. A request that cannot be clearly explained should not be signed.
Phishing campaigns commonly use airdrops, whitelist access, free mints, refund claims, supposed account problems and token-migration notices to bring users to pages that request connections, signatures or direct token transfers. The familiar theme is urgency combined with a reward or warning, pushing users to treat a signature as harmless account verification rather than a potential asset authorization.
Unlimited allowances deserve priority review
The recommended response is to periodically review wallet permissions, starting with unlimited allowances on high-value tokens, NFT-wide approvals, unknown spenders and links to applications no longer used. Revoking an approval generally requires an on-chain transaction and a network fee, since the earlier permission was recorded on-chain.
The briefing’s containment guidance is more urgent when suspicious activity has already appeared. Users should stop interacting with the suspected website and avoid any follow-up prompt described as a repair, security check or verification process. They should revoke known malicious approvals using a trusted interface and move remaining assets to a safer wallet if the scope of the compromise is unclear or transfers continue.
Changing an app password or reinstalling wallet software would not stop a party relying on an existing token allowance. In cases involving a potentially exposed seed phrase or private key, moving funds to a newly created wallet is also necessary, but the briefing centers on the separate problem of permissions granted by the user’s own wallet.
Separating long-term holdings from wallets used for frequent interactions can limit the funds available to a harmful contract approval. The document also recommends setting approval amounts near the amount actually needed rather than defaulting to unlimited access.
Poisoned histories can redirect large transfers
The second major threat covered in the briefing is address poisoning, a tactic designed to exploit users who copy a destination address from their transaction history. Attackers create addresses that resemble a target address at the beginning and end, then send a zero-value or tiny transaction to place the look-alike address in the victim’s recent activity.
A user who checks only a few characters may later select the attacker’s address from the history and send funds to it. Blockchain addresses are long strings, and abbreviated wallet displays can reinforce the unsafe habit of verifying only the visible prefix and suffix.
The briefing says transaction history should not serve as an address book for large transfers. Deposit and payment addresses should instead be obtained from verified channels, pasted into the wallet, and checked in full before confirmation. A small test transfer can provide an additional safeguard before a large payment, followed by another complete review of the destination address before sending the main amount.
The supplied material cites USENIX research published in early 2026 that recorded more than 270 million address-poisoning attempts on Ethereum, as well as a December 2025 incident in which a victim reportedly lost about $50 million in USDT after relying on contaminated transaction history. Those examples show why a zero-value transfer should be treated as potential manipulation rather than meaningless wallet activity.
Account controls can add checkpoints
The briefing contrasts irreversible blockchain transfers with account-based platforms that can add controls before a withdrawal completes. It describes address books that restrict API withdrawals to pre-saved destinations, along with 24- to 48-hour cooling-off periods for newly added withdrawal addresses.
Additional account protections include multi-factor authentication for logins and withdrawals, separate funds passwords, dynamic verification triggered by unusual activity, and withdrawal locks after changes to key security settings. The guidance also recommends lower daily withdrawal limits, anti-phishing codes in account communications and periodic reviews of API-key permissions, with unused keys deleted.
The document references contract-review tools that generate structured risk reports across more than 57 vulnerability categories, including owner privileges, blacklists, token-minting powers and transfer taxes. Such tools can help identify concerning contract features, though they do not replace checking the authorization a wallet is being asked to grant.
Passkeys offer another layer for account access by tying authentication to a specific website domain and requiring device-based biometric verification, such as a fingerprint or facial scan. That domain binding can make phishing pages less able to capture login credentials through look-alike websites, while approval limits and careful address verification remain the direct defenses against the two on-chain threats described in the briefing.
Level up wallet safety with Toobit’s security guide: learn essential crypto wallet protection tips before your next transaction.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
