🔐 Custody
Token approvals: the silent drainer
Every time you use a dapp — swap on a DEX, mint an NFT, stake something — you're often asked to "approve" a token first. That approval is a standing permission letting a smart contract move that token out of your wallet whenever it wants, not just for the transaction in front of you.
A malicious or exploited contract can use an old "unlimited" approval to drain your wallet weeks later, with zero new signature from you. You won't see it coming because you already said yes, months ago, without reading the fine print.
Two habits fix this. First, actually read what a signature grants before you click — not just the popup's pretty design, the permission itself. Second, periodically revoke approvals you no longer need, using a checker tool built for exactly that. An old unlimited approval to a site you forgot about is a leash on your funds someone else is holding.