Insightful ♦️ Profile picture
Making you more insightful about Airdrops & Web3 | I actually disclose sponsored content | Info Asymmetry Maxi | No GM posts/noise only alpha | @WolvesDAO wolf

Aug 25, 2022, 11 tweets

Token approvals are one of the most important concepts to understand in #crypto yet it feels one of the most overlooked

Whether thats the default unlimited er20 approval your giving #uniswap

Or the 'set approval for all' your giving to #Opensea to sell your #nft . . . .

Giving these approvals to something malicious can cost you every token you've given approval for in that wallet

this is why its important to:
1. check and revoke your approvals regularly with sites like revoke.cash
etherscan.io/tokenapprovalc…

youd be surprised what you many have approved

for example if you do a swap on 1inch you do a sign and a approval in the same transactions and it will set an unlimited allowance for that token without giving you the option to change it before hand

a lot of defi applications have unlimited approval set by default as a user convenience feature so you dont have to pay another gas fee in the future to sign for another approval however...

2. manually editing the token approval amount on defi apps to the max amount youll think youll need to swap and the most your willing to lose if there was a smart contract exploit

see the mutichain WETH explot as an example cointelegraph.com/news/multichai…

Make sure your interacting with the right website and smart contract when signing a 'set approval for all' for your nfts

A lot of 'hacks' happen this way where the victim believes they are interacting with a legitimate site but dont check the contract

they end up giving approval to the hackers malicious contract instead to move/ steal the nfts on their behalf

Also understanding the difference between signing a signature and signing a transaction that costs gas is important

-signatures are generally less high risk as its required often to sign into dapps to verify the contents of that respective wallet

However its still possible to be exploited via signature

might do a video on everything explained above in the future

let me know what you think or what you think more people need help understanding

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling