✅ What is an Approval Scam?
An approval scam is a type of crypto fraud where attackers trick a user into signing a transaction that grants a malicious smart contract permission to spend tokens from the user's wallet. This permission, known as a "token approval" or "allowance," is a standard feature of tokens like USDT TRC20, USDC, and others. Once the approval is granted, the attacker can transfer the approved tokens to their own address at any time.
The scam often disguises the approval as a harmless action — such as "connecting" a wallet, "claiming" an airdrop, "verifying" identity, or "logging in" to a site. The user signs the transaction without realizing they are giving away control of their tokens.
Approval scams are especially prevalent on the TRON network due to the widespread use of USDT TRC20 and the low transaction fees, which make it cheap for attackers to drain funds.
An approval is a persistent permission. Once you approve a contract to spend your tokens, that permission remains until you explicitly revoke it. This means a single malicious approval can lead to loss of funds days or weeks later — even if you never visit the scam site again.
⚙️ How an Approval Scam Works
Approval scams exploit the token approval mechanism that is built into TRC20, ERC20, and other token standards. Here's a step-by-step breakdown:
- Step 1: Luring the Victim. Attackers promote fake airdrops, high-yield farming, exclusive NFT mints, or "wallet verification" requirements. They use social media (X, Telegram, Discord) and sometimes hacked official accounts to gain credibility.
- Step 2: Wallet Connection. The victim connects their wallet (TronLink, Trust Wallet, MetaMask, etc.) to the fake site. This connection itself is safe — it's just a read-only link.
- Step 3: The Approval Trap. The site prompts the user to sign a transaction, often with a misleading message like "Claim Rewards," "Verify Wallet," or "Connect." In reality, this transaction calls the token's approve() function, giving the attacker's contract permission to spend a specified amount (often unlimited) of the user's tokens.
- Step 4: The Drain. Once the approval is on-chain, the attacker can call transferFrom() to move the tokens from the victim's wallet to their own. This can happen immediately, or the attacker may wait — because the approval remains valid until revoked.
TRON-Specific Details
On TRON, TRC20 tokens use the approve function to set an allowance. The attacker's contract address becomes the "spender." The user signs a transaction that includes the spender address and the allowance amount. The victim often sees a transaction pop-up in TronLink that says "Approve USDT" but may not fully understand what they are approving.
Once approved, the attacker can use transferFrom to move the tokens. Because TRON has fast block times, the drain can happen within seconds.
Before signing any approval, check the spender address and the allowance amount. If the amount is set to 2^256 - 1 (unlimited) and you don't fully trust the site, do not proceed. Use a block explorer like TronScan to verify the contract address.
🎭 Common Scenarios Where Approval Scams Occur
Scammers promote a token airdrop. To "claim" the tokens, users must approve a transaction that actually grants spending rights to the scammer's contract.
Attackers create popular NFT collections and direct users to mint on a malicious site. The mint transaction includes a hidden approval.
Fake staking or liquidity mining platforms that require users to approve their tokens before "depositing." The approval grants the drainer full access.
Hacked official accounts (Twitter, Discord) post links to approval scam sites, leveraging the account's trust to lure victims.
Emails that appear to be from exchanges or wallet providers, urging users to "verify" their wallet or claim rewards on a fake site.
Attackers buy ads on search engines to appear at the top for queries like "Uniswap" or "TronLink," directing users to fake sites.
The "Infinite Approval" Trap
The most dangerous type of approval is an unlimited approval. This allows the spender to transfer the entire balance of the approved token — not just a specific amount. Scammers often request unlimited approvals to maximize their theft. If you see "unlimited" or a very large number (like 2^256 - 1) in the approval transaction, treat it as a major red flag unless you are interacting with a trusted, well-audited protocol.
🔄 Approval Scam vs. Wallet Drainer: What's the Difference?
These terms are often used interchangeably, but they refer to different aspects of the attack:
- Approval Scam — The act of tricking the user into signing an approval transaction. This is the method used to obtain permission.
- Wallet Drainer — The automated script or smart contract that uses the approval to transfer funds. This is the mechanism that executes the theft.
In practice, they work together: the approval scam is how the victim grants permission, and the drainer is what uses that permission to steal the tokens. Many attacks combine both: a fake site prompts an approval (scam), and then a drainer contract automatically sweeps the tokens (drainer).
You can only be drained if you have previously approved a spender. By regularly revoking unused approvals, you break the chain and prevent drainers from working — even if you were tricked into approving in the past.
🚩 How to Spot an Approval Scam
| Red Flag | What to Look For |
|---|---|
| "Unlimited" or Huge Allowance | If the approval amount is set to an enormous number (e.g., 2^256 - 1), the spender can take all your tokens. Only trust this with well-known protocols. |
| Mismatched Spender Address | Check the contract address that will be approved. If it doesn't match the official protocol address, it's almost certainly a scam. |
| Unsolicited Offers | If someone reaches out to you with a "great opportunity" that requires an approval, it's likely a scam. |
| Vague Transaction Descriptions | In your wallet, the transaction might say "Approve USDT" but not specify the spender or amount clearly. Always expand the details. |
| Pressure to Act Fast | Scammers create urgency ("limited time") to prevent you from verifying the details. |
| Fake Domain Names | Check the URL carefully. Scammers use typosquatting (e.g., "uniswarp.com" instead of "uniswap.org"). |
| Unverified Contract Code | On TronScan, if the contract code is not verified, be very cautious. While verified code doesn't guarantee safety, unverified code is a strong warning. |
What an Approval Transaction Looks Like in TronLink
When you're about to sign an approval in TronLink, you'll see:
- Contract: The token contract (e.g., USDT TRC20 address).
- Spender: The contract that will receive approval to spend your tokens.
- Amount: The allowance (could be "unlimited").
If you don't recognize the spender or the amount seems excessive, do not sign.
Many users blindly sign transactions without reading the details. Take the extra 10 seconds to verify the spender and amount. It could save your entire portfolio.
🛡️ How to Protect Yourself from Approval Scams
Essential Security Practices
-
1
Revoke Unused Approvals Regularly
Use Revoke.cash (supports TRON) or TronScan's approval manager to review and remove any approvals you don't recognize or no longer need. Make this a monthly routine.
-
2
Never Approve Unlimited Amounts Unless Trusted
If a site asks for unlimited approval, ask yourself if you fully trust it. For reputable protocols, it's often safe, but always double-check the contract address.
-
3
Verify the Spender Address
Before signing, check the spender address against the official contract address of the protocol you're using. A mismatch is a clear sign of a scam.
-
4
Use a Separate Wallet for dApps
Keep your main holdings in a hardware or "cold" wallet and use a separate "hot" wallet with limited funds for interacting with dApps and sites you don't fully trust.
-
5
Stay Skeptical of "Free" Offers
If an offer requires you to approve a token before receiving something, it's almost certainly a scam. Legitimate airdrops usually deposit tokens directly without requiring approvals.
-
6
Use a Hardware Wallet
Hardware wallets require physical confirmation for transactions, giving you a chance to review details on the device screen. This adds an extra layer of verification.
-
7
Educate Yourself and Stay Updated
Follow crypto security news and communities to learn about new scam tactics. Awareness is your best defense.
How to Revoke Approvals on TRON
Revoking an approval cancels the permission granted to a spender. Here's how:
- Using Revoke.cash: Visit Revoke.cash, connect your wallet, select TRON network, and you'll see a list of active approvals. Click "Revoke" for any you want to remove.
- Using TronScan: Go to your wallet address on TronScan, click the "Tokens" tab, then "Approvals." You'll see all active approvals with options to revoke.
- Cost: Revoking an approval costs a small network fee (TRX). This is a tiny price to pay for security.
Set a recurring calendar reminder to review and revoke approvals every month. Many scams rely on approvals that users forgot they ever granted. Stay ahead of them.
🚨 What to Do If You've Been Scammed
If you suspect you've fallen for an approval scam, act immediately:
- Revoke the approval immediately using Revoke.cash or TronScan. This stops the attacker from taking more tokens.
- Move remaining assets to a new, secure wallet. Generate the new wallet offline and keep the seed phrase safe.
- Stop all interactions with the site that caused the scam.
- Report the incident to the platform where you encountered the scam (Telegram, X, etc.) and to law enforcement if the loss is significant.
- Be wary of recovery scams — scammers may contact you offering to "recover" your funds. Do not engage.
Once tokens are sent to an attacker's address, they are almost impossible to recover. The best defense is to never sign an approval you don't fully understand and trust.
🌐 Why Approval Scams Thrive in Crypto
Several factors make approval scams particularly effective:
- User Confusion. Many users don't fully understand what a token approval does or how to check transaction details.
- Irreversibility. Once a transaction is confirmed, it cannot be undone.
- Pseudonymity. Attackers are hard to trace and prosecute.
- Low Cost. Deploying a fake site and executing approvals is cheap compared to potential returns.
- FOMO and Greed. Scammers exploit emotions to rush victims into signing without thinking.
As the crypto ecosystem grows, so does the sophistication of these attacks. Staying informed and adopting a security-first mindset is essential.
For more on crypto security, read our guides on Token Approval, Wallet Drainer, and Phishing Scams.