toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

On-chain approvals drain wallets without private keys

2026-09-23 09:26

A joint security briefing published Sept. 23 warns that wallet funds can be drained without a stolen seed phrase or private key when users have already granted a malicious or compromised smart contract permission to move their assets. The document focuses on token approvals, off-chain signatures and address poisoning, arguing that routine wallet habits can leave users exposed long after they close a website or delete an app.

On EVM-compatible networks, an ERC-20 approval is more than a one-time confirmation for a swap. It can create a standing authorization that lets an approved address or contract transfer tokens through the transferFrom function, up to the approved limit, without generating a fresh prompt for the wallet owner.

That structure can turn a small intended trade into a much larger exposure. The briefing gives the example of a user seeking to swap 100 USDC but approving an unlimited allowance instead. A malicious operator, or an attacker exploiting a vulnerability in the approved contract, could then attempt to move far more than the original 100 USDC.

Chainalysis estimated in its 2026 Crypto Crime Report that scams took about $17 billion in cryptocurrency during 2025. The figure covers a broad range of fraud, but the briefing places wallet authorization abuse among the practical threats that users can reduce through tighter control of approvals and signatures.

Approvals can outlive the app or website

The briefing stresses that on-chain permissions remain active until they are revoked on the blockchain. Uninstalling a wallet application, disconnecting from a decentralized application, changing phones or resetting passwords does not cancel an approval that has already been recorded in a smart contract.

That creates a gap between how users may perceive a wallet connection and how permissions operate technically. Connecting a wallet to a website is usually only an initial step. The later transaction or signature request determines whether the site receives authority to spend tokens, manage NFTs or use a signed authorization at a later point.

NFT owners face a related risk through setApprovalForAll, a standard function that can authorize an operator to manage every NFT held by the wallet under a particular collection contract. Unlike an approval tied to one token ID, the permission can cover an entire group of collectibles from the same contract.

The document also flags Permit and Permit2 signatures. These mechanisms allow users to sign a message off-chain rather than submit an approval transaction directly on the network. The signature does not consume gas when it is created, but it can be used later to establish or exercise token-transfer rights. That convenience can make the request appear less consequential than a conventional on-chain approval.

Users should check the target receiving the authorization, the asset involved, the amount and the breadth of the requested permission before signing, the briefing says. A request that cannot be clearly explained should not be signed.

Phishing campaigns commonly use airdrops, whitelist access, free mints, refund claims, supposed account problems and token-migration notices to bring users to pages that request connections, signatures or direct token transfers. The familiar theme is urgency combined with a reward or warning, pushing users to treat a signature as harmless account verification rather than a potential asset authorization.

Unlimited allowances deserve priority review

The recommended response is to periodically review wallet permissions, starting with unlimited allowances on high-value tokens, NFT-wide approvals, unknown spenders and links to applications no longer used. Revoking an approval generally requires an on-chain transaction and a network fee, since the earlier permission was recorded on-chain.

The briefing’s containment guidance is more urgent when suspicious activity has already appeared. Users should stop interacting with the suspected website and avoid any follow-up prompt described as a repair, security check or verification process. They should revoke known malicious approvals using a trusted interface and move remaining assets to a safer wallet if the scope of the compromise is unclear or transfers continue.

Changing an app password or reinstalling wallet software would not stop a party relying on an existing token allowance. In cases involving a potentially exposed seed phrase or private key, moving funds to a newly created wallet is also necessary, but the briefing centers on the separate problem of permissions granted by the user’s own wallet.

Separating long-term holdings from wallets used for frequent interactions can limit the funds available to a harmful contract approval. The document also recommends setting approval amounts near the amount actually needed rather than defaulting to unlimited access.

Poisoned histories can redirect large transfers

The second major threat covered in the briefing is address poisoning, a tactic designed to exploit users who copy a destination address from their transaction history. Attackers create addresses that resemble a target address at the beginning and end, then send a zero-value or tiny transaction to place the look-alike address in the victim’s recent activity.

A user who checks only a few characters may later select the attacker’s address from the history and send funds to it. Blockchain addresses are long strings, and abbreviated wallet displays can reinforce the unsafe habit of verifying only the visible prefix and suffix.

The briefing says transaction history should not serve as an address book for large transfers. Deposit and payment addresses should instead be obtained from verified channels, pasted into the wallet, and checked in full before confirmation. A small test transfer can provide an additional safeguard before a large payment, followed by another complete review of the destination address before sending the main amount.

The supplied material cites USENIX research published in early 2026 that recorded more than 270 million address-poisoning attempts on Ethereum, as well as a December 2025 incident in which a victim reportedly lost about $50 million in USDT after relying on contaminated transaction history. Those examples show why a zero-value transfer should be treated as potential manipulation rather than meaningless wallet activity.

Account controls can add checkpoints

The briefing contrasts irreversible blockchain transfers with account-based platforms that can add controls before a withdrawal completes. It describes address books that restrict API withdrawals to pre-saved destinations, along with 24- to 48-hour cooling-off periods for newly added withdrawal addresses.

Additional account protections include multi-factor authentication for logins and withdrawals, separate funds passwords, dynamic verification triggered by unusual activity, and withdrawal locks after changes to key security settings. The guidance also recommends lower daily withdrawal limits, anti-phishing codes in account communications and periodic reviews of API-key permissions, with unused keys deleted.

The document references contract-review tools that generate structured risk reports across more than 57 vulnerability categories, including owner privileges, blacklists, token-minting powers and transfer taxes. Such tools can help identify concerning contract features, though they do not replace checking the authorization a wallet is being asked to grant.

Passkeys offer another layer for account access by tying authentication to a specific website domain and requiring device-based biometric verification, such as a fingerprint or facial scan. That domain binding can make phishing pages less able to capture login credentials through look-alike websites, while approval limits and careful address verification remain the direct defenses against the two on-chain threats described in the briefing.


Level up wallet safety with Toobit’s security guide: learn essential crypto wallet protection tips before your next transaction.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.