Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

Malicious token approvals

A transaction grants a spender authority over assets already held by the victim.

Reference note · Sources below

Research articles and reference entries are published in English. Navigation is available in seven languages.

In this article
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A transaction grants a spender authority over assets already held by the victim.

Why it matters

The spender can wait and transfer tokens later without another signature.

What to check

Record token, owner, spender, limit and transaction hash, then revoke unnecessary authority.

Sources

Related reading

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet