Theft

Malicious Token Approval: The First 60 Minutes After Funds Move

A laptop keyboard in dark lighting, representing a compromised crypto wallet
In brief

If assets are actively being transferred through a malicious token approval, the priority is to stop further transfers and move the remaining assets to a new wallet created on a secure device. Then revoke dangerous permissions and record the TxIDs. Revoking an approval does not return assets that have already been stolen and will not help if the seed phrase was compromised. See emergency response for the urgent process.

First identify the mechanism

A token approval gives a smart contract permission to spend tokens. While the allowance remains active, an attacker can transfer the balance without obtaining a new signature for every transaction. In this scenario, revoking permissions on every network where you used the wallet can help.

If the seed phrase was stolen, or a malicious bot immediately transfers any gas sent to the wallet, revoking approvals will not solve the problem because the attacker already has the keys. The only durable response is to treat the address as compromised and never fund it again. If you are unsure, act on the worst-case assumption while preserving evidence for blockchain analytics.

Permit and Permit2 signatures are another possibility. These permissions can remain off-chain until used. Revoking an old on-chain approval may therefore be insufficient; the remaining tokens need to be moved away from the address covered by the signature.

The first hour: checklist

  1. Open a blockchain explorer and record outgoing TxIDs, recipient addresses, and networks.
  2. Create a new wallet on a clean device. Do not enter or photograph the seed phrase anywhere else.
  3. Move the remaining assets to the new address, starting with the most liquid assets.
  4. Revoke dangerous approvals. Type revoke.cash directly into the browser instead of using an advertisement or the first search result.
  5. Repeat the revocation on every network where the wallet held assets.
  6. Change the email credentials and 2FA for connected exchanges if the same device or phishing incident may have exposed them.

Legitimate approval-revocation services do not ask for a seed phrase. If a website or helper requests the recovery phrase, it is an attack. For the related question of recovery without a complete phrase, see when partial seed recovery may be realistic.

Evidence to preserve for investigation and freezing requests

Preserve the TxIDs, addresses, timestamps, a screenshot of the phishing page, the list of networks, and the contracts that received permission to spend tokens. This can accelerate analysis and freezing requests to destination exchanges if the assets have not yet moved. Partial recovery is not guaranteed, especially after mixers or rapid OTC transfers.

GoalWhat may be realistic in the first hour
Stop further transfersNew wallet plus approval revocation
Preserve evidenceTxIDs, addresses, networks, phishing screenshot
Freeze assets at an exchangeOnly while the assets remain in an exchange account
Recover assets already transferredNot guaranteed

If some assets reached a centralized exchange, it may be appropriate to pursue exchange account unfreezing and exchange engagement with a TxID package in parallel, but first close the vulnerability in your wallet.

What not to do

  • Do not send more ETH for gas to an address that is being drained if the gas is transferred out immediately.
  • Do not install recovery extensions or bots found through search.
  • Do not reuse the compromised address for new deposits.
  • Do not submit the seed phrase through a website form or chat.

Do not spend the first hour arguing in comments or trying to assign blame. The window while assets remain at the address is shorter than it appears, particularly on low-cost networks.

Limitations

Risks and limitations

  • Some assets may already have been transferred, and recovery is not guaranteed.
  • Using a seed phrase on an infected device can increase the loss.
  • Revoking an approval does not cancel off-chain permit signatures or address a stolen seed phrase.
  • Fake approval-revocation websites may drain the remaining balance.
Sources

Sources used

Next

Related resources

ServiceEmergency responseBack to the blog
Next step

Need an assessment of your situation?

Briefly describe what happened — without seed phrases or private keys. We will outline possible routes and assess their feasibility.

Request a free assessment
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.