How to Handle a Suspicious Malicious Wallet Approval Before Your Assets Are Stolen

 / 
1

Your assets haven't been lost yet, but the approval has been granted. The window of risk is narrow, and proactively revoking the approval is the only solution. A few simple steps can quickly lock down the risk.

Prerequisites

  • You know which network (ETH, BSC, Polygon, etc.) you granted the malicious contract approval on.
  • You still have the native token of that network (ETH/BNB/MATIC) in the wallet to pay for gas fees.
  • Have a receiving address ready to retrieve your assets (a brand new, secure wallet address).

Step 1: Immediately Transfer Any Movable Assets

Don't worry about anything else. First, transfer all assets that haven't been taken yet to another new address that has never been connected to any DApp.

How to do it:

  1. Create a new wallet (or use a hardware wallet), and securely record the seed phrase.
  2. Transfer all assets from the old wallet at once, leaving only enough for gas fees.
  3. Don't deliberate which assets are at risk—move them all. Secure first, investigate later.

Completion criteria: The old wallet balance is zero (only a tiny amount reserved for gas), and all assets show up in the new wallet address.

Risk warning: If anyone pops up now claiming they can "help you find the hacker," it's 100% a secondary scam. In the decentralized world, there is no "platform support" that can freeze on-chain assets. Only you can stop further loss. According to security guides, over 60% of asset thefts are not due to private key leaks but because users signed malicious approvals.

Step 2: Use Tools to Revoke Risky Approvals

Once assets are moved, the old wallet should not be used anymore. But the approval record remains. If you don't revoke it, it's like leaving the keys to an empty house with a thief—if you ever send money to that address again, they can still take it directly.

How to do it: Open Revoke.cash, connect your old wallet, and switch to the corresponding network. The page will list all active approvals for that address, sorted from newest to oldest. Find the suspicious one (usually a contract address you don't recognize or just interacted with). Click "Revoke" and pay the gas fee to execute the on-chain transaction.

Completion criteria: The Revoke.cash page no longer shows that suspicious approval record, and the corresponding on-chain transaction status is "Success".

Step 3: Continuously Monitor the Old Address

After revoking approvals, the old wallet address remains publicly visible on-chain. Scammers might try again later or use other methods to attack. Add the old address to your block explorer watch list (e.g., Etherscan's Watch List) so you'll receive email alerts for unusual transactions.

Completion criteria: The old address shows "No risk approvals" on Revoke.cash, and the watch list has been added.

Verification After Completion

Open Revoke.cash, enter the old wallet address, and switch to the corresponding network. If the top of the page shows "0 approvals" or "No risk approvals," you're done. The entire process takes about 5–10 minutes, with confirmation that the on-chain transaction status is "Success".

Follow-Up Notes

Once you've confirmed the old wallet is completely safe, abandon it entirely. Do not send any assets to that address again. Migrate all future activities to the new wallet.