You are about to confirm a transaction on a DApp when your wallet pops up a red warning: "This contract has not been audited." You hesitate: confirm or not?

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Direct answer: If this transaction involves a token approval (Approve) or an EIP-7702 delegation signature, you must reject it. Do not even think twice. Stop first, check carefully, then act.
First understand: Why the wallet shows this warning
Decentralized wallets such as TokenPocket and Trust Wallet do not block transactions by themselves. However, their built-in security services such as GoPlus and BlockSec analyze the transaction intent before you connect to a DApp or sign anything.
"Contract not audited" means:
The contract code has not been reviewed by any well-known third-party security firm.
It may contain vulnerabilities, backdoors, or the ability to directly take your assets.
TokenPocket has officially warned about this: If the code is unaudited, it can directly take user assets or arbitrarily freeze participating accounts. This is not fearmongering. After EIP-7702 went live, security firms observed that during some periods more than 80% to 97% of EIP-7702 authorizations went to malicious contracts.
Minimum viable steps
Step 1: Confirm what type of operation you are signing when the warning appears
Before you click "Confirm," first check what the wallet popup actually says:
| Operation type | Wallet warning example | Recommended action |
|---|---|---|
| Token approval (Approve) | "Requesting approval to spend USDT" | Check the approval amount. If it is "unlimited," reject immediately. If it is a small amount and you are actively interacting with a well-known protocol such as Uniswap or Aave, you may consider it carefully. |
| EIP-7702 delegation authorization | "Delegate account to contract" / "Upgrade to smart account" | Regardless of whether an audit warning appears, always reject unless the address is on the wallet's official whitelist. |
| Normal transaction (Transfer/Swap) | "Confirm transaction" | This type of operation normally does not trigger an "unaudited contract" warning. If it does, it means the contract you are interacting with has a problem. Stop the operation. |
Completion standard: You can clearly say what you originally intended to do: approve tokens, delegate an account, or make a normal transfer.
Step 2: If the popup involves approval or delegation, stop here and do two things
First confirm: Is the address you are interacting with on the official whitelist?
For EIP-7702, wallets usually whitelist specific delegation contracts. The official Ethereum EIP-7702 guide also clearly states that "dapps should not expect to directly request EIP-7702 authorization signatures. Integration should be done through standardized wallet interfaces such as ERC-5792 and ERC-6900." If you are asked to directly sign an EIP-7702 authorization, that is a danger signal.
Use Revoke.cash to check the contract. It currently supports EIP-7702 authorization detection, so you can see whether the contract has been flagged before.
Use eip7702.app for a quick check: enter the address to query authorization records. Only enter the address; do not connect your wallet.
Completion standard: You can confirm that the contract address is on the wallet's official whitelist, or that it is a widely verified well-known protocol. If no record can be found, treat it as not passed by default.
Step 3: If no record can be found, or the warning says "unaudited"
Do not click "Confirm." Simply close the popup.
Fireblocks' security guide points out: "A reckless approach would allow delegation as openly and freely as possible, but that would very likely end with the loss of all funds. One malicious delegation is enough."
TokenPocket's advice is even more direct: "When a DApp makes a contract call to obtain approval or otherwise gain high-risk authorization, a contract call risk warning will appear in the wallet. When you encounter such an alert, you need to stop the operation."
Completion standard: You have successfully closed the popup and have not authorized or delegated anything to an unaudited contract. The transaction is canceled and your funds are safe.
Troubleshooting
Case A: The wallet says "contract not audited," but I am interacting with a well-known protocol such as Uniswap
If you are sure it is Uniswap's official contract address, the wallet's security service may have delayed recognition or may be overly strict. You can:
Check the contract address on Uniswap's official website to see whether it matches.
If it does match, you may consider manually adjusting the wallet security settings, or simply ignore the warning for now.
Case B: I clicked "Reject" once, and then the DApp stopped working
That is normal. Rejecting authorization means you cannot use that DApp's features. If the DApp is legitimate, it should support operation through official wallet interfaces such as ERC-5792 instead of directly asking you to sign a delegation authorization. If a legitimate DApp refuses service just because you rejected direct authorization, then it does not follow Ethereum best practices.
Case C: I already clicked "Confirm" on an unaudited contract
Immediately go to Revoke.cash or your wallet's authorization management page and revoke the authorization for that contract.
If it is an EIP-7702 delegation, you need to send a type 0x04 transaction pointing the delegation address to the zero address to clear the delegation.
If you are still worried, move the main assets from that address to a new wallet.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Final verification
How to verify that you have completed the operation correctly: You successfully rejected the popup and the transaction was not completed. Or, after verifying that the contract address is indeed on the official whitelist, you approved the operation and there were no abnormal fund movements such as unauthorized token transfers or unexpected delegation records on the account.


