Applications you no longer use may retain spending permission. Checking the network, spender and limit in the right order helps you identify which approvals to remove.
Revoking a token approval changes spending permission recorded on the blockchain. Removing an application's wallet connection is not enough. Before you act, match the account, network and authorized address: the same token name can refer to different contracts on different networks.
This guide covers token approvals on Ethereum and other EVM networks. Choosing a wallet, backing up recovery words and recovering lost assets are separate tasks. The aim here is to read the permissions that remain on your account and remove those you no longer need. Before signing a new request, use the crypto phishing and fake-token checks to separate domain verification, contract matching and the authority being requested.
Why disconnecting a wallet does not revoke an approval
Connecting lets an application use your address in its interface and suggest transactions. A token spending approval is recorded separately for a particular spender in a particular token contract. Closing the application's tab does not erase that permission. MetaMask's explanation of disconnection makes the same distinction.
| Action | What changes? | What stays unresolved? |
|---|---|---|
| Disconnect an application | The wallet's connection to the site is removed. | Existing onchain token permission is not erased. |
| Revoke a token approval | Permission for the selected token and spender is removed. | A completed transfer is not reversed. |
| Delete the wallet application | The local application is removed. | Onchain permissions and records remain. |
Five steps to check and revoke token approvals
1. Select the right account and network
Copy the account's public address from your wallet. Using the same address on Ethereum, Base and BNB Smart Chain does not make their approvals shared. Check each network separately. Reading the address does not require a private key or recovery words.
Open the tool's official address yourself instead of following a suspicious message. A page asking for recovery words to “validate” your wallet is not an approval check. If you are unsure how your keys are protected, start with the custody and signing checks in our wallet selection guide.
2. Read the spender, token and limit together
The spender is the address authorized to use tokens; the allowance is the amount it may use. Do not confuse the token contract with the spender. Compare the address with the project's official contract information instead of relying on a familiar name or logo.
As explained in Revoke.cash's instructions, you can look up an address and filter permissions by network, spender and date. MetaMask Portfolio users can check Spending Caps under Overview. Screen labels and network support may change, so read the selected network again when using the tool.
Our suggested order at KriptoMeta is to inspect unfamiliar spenders first, applications you have stopped using next, then limits larger than you need. An unlimited approval is not proof of fraud; it means the granted permission is broad. The displayed token balance and the allowance are different values.
3. Verify what the revocation will change
Select the permission and choose Revoke to open your wallet's transaction preview. For a standard ERC-20 approval, the intended change is to set that spender's allowance to zero. Check the token and spender addresses rather than trusting the button label alone.
For example, you may once have authorized 5,000 sample tokens for a transaction involving only 80. Removing the remaining permission is not a request to transfer your tokens elsewhere. If the confirmation screen shows an unexplained transfer or a new high limit, do not sign. The amounts in this example are hypothetical.
4. Check the network fee and submit
An onchain revocation requires a network fee. You need the appropriate native asset on the network where the transaction takes place. Ethereum requires ETH; a balance on Ethereum mainnet does not pay fees on a different network. MetaMask's Portfolio documentation also notes that revocation requires a transaction and gas.
For an Ethereum estimate, you can use our gas fee calculator. Compare the result with your wallet's transaction estimate. Do not assume a fixed 21,000 gas for an approval revocation: contract execution changes the requirement. Batch services may charge a service fee on top of network fees, so check the displayed total.
5. Confirm the result onchain
A signature does not prove successful execution. Open the transaction hash and check its status. A failed or pending transaction is not evidence that permission has been removed. Refresh the approval list and inspect the remaining permission for the same network, token and spender.
Our transaction tracking guide explains hashes and status fields. For Ethereum's record screens, the Etherscan review helps you interpret what the interface shows.
Why Permit signatures need another check
A signature that costs nothing is not necessarily a harmless sign-in message. Permit signatures can be submitted onchain later to authorize spending. An unused signature may not appear in the standard approval list; its absence does not prove you never signed it.
With Permit2, the token's base approval to the Permit2 contract and the application's permission through that contract are separate layers. A suspicious signature requires checking which layer changed and whether the signature remains valid. Setting one displayed allowance to zero does not establish that every signature risk has ended. Consult the wallet's and protocol's current signature invalidation methods.
Problems that revocation cannot fix
If recovery words were exposed: Revoking approvals does not invalidate the attacker's key. Avoid repeatedly adding funds to pay gas: a sweeper may take those deposits too. Setting up an account with new keys on a clean device is a separate security process.
Our seed phrase storage guide explains backup responsibilities. Revoking an approval cannot recover a completed transfer. An empty approval list does not certify that the account is safe from every type of attack.


















