Precautions When Connecting Your Wallet to a DApp

When using DApps, you may be asked to perform actions such as connecting your wallet, approving token usage, or signing transactions and messages. These are necessary steps for using many DApp features, but proceeding without checking the details can result in the loss of your assets.

Simply connecting your wallet does not give the DApp access to your private key or allow it to move your assets. However, you should carefully review any approvals, transactions, and signature requests that follow the connection.

What to Check Before Connecting

Verify the Official URL

Always make sure the URL of the DApp you are connecting to matches the one officially provided. Even if a site looks identical to the real thing, it could be a phishing site with a slightly different URL. Avoid connecting to or interacting with unfamiliar sites, DApps with no official announcement, or DApps promising unnaturally high returns — always use the official URL or in-app browser as directed.

Check the Permissions and Approvals Requested

Make sure that any permissions or token approvals requested by the DApp are appropriate for what it is supposed to do. For example, be cautious if a DApp that only needs to display your balance is requesting permission to transfer your tokens.

Precautions When Signing

Don't Approve Without Reading the Details

When a signature or transaction confirmation screen appears, carefully review the details before proceeding, such as the destination address, amount, token, and function being called. Be especially cautious if you are being rushed into signing multiple requests one after another.

What Is Blind Signing?
In some cases, a wallet may display a signature request as an unreadable string of data instead of clearly showing what you are authorizing. This is known as "blind signing."

Blind signing increases the risk of approving a transaction or message without fully understanding its contents. In 2023, for example, the Ledger Connect Kit library used by many DApps was compromised, and attackers used the compromised library to present malicious transactions to users. Users who signed those transactions had their assets stolen.

Be Especially Careful with "Unlimited" Approvals

When requesting permission to use your tokens, some DApps ask for an approval with no spending limit — an "unlimited" approval. While this is convenient because it allows repeated transactions without requesting another approval each time, it also carries a risk. If the DApp is later compromised or behaves maliciously, it may be able to transfer more of the approved token than you originally intended.

What to Review After Connecting

Once a token approval is granted, it generally remains in effect until it is changed or revoked. We recommend periodically checking your active token approvals and revoking those you no longer need or no longer trust, using Revoke.cash.

If Something Goes Wrong

If you realize that you have connected to a suspicious DApp or granted a token approval you do not trust, revoke the relevant approval on Revoke.cash as soon as possible to prevent further unauthorized transfers.

If your assets have already been transferred by a confirmed blockchain transaction, revoking an approval cannot reverse the transaction or recover the stolen assets. However, promptly checking and revoking any remaining approvals can help prevent further unauthorized transfers from the same wallet.

Related articles: Revoking Unnecessary Approvals with Revoke.cash / Unrecognized Transfers Shown in My Activity / What's the Difference Between Web2 and Web3, DApps, DeFi, and DEX?

Back to For Safe Use