Swap security

Why two allowance scanners can show different results

Explain differences between allowance tools by checking network coverage, indexing and the permission types each tool recognizes.

Two allowance scanners can disagree because they cover different chains, token standards, historical events or authorization systems. Compare the actual permission being measured before deciding one result proves the account is clean.

Check the scope

  • Same account and network?
  • Same token contract and spender?
  • Current allowance or historical approval event?
  • Standard ERC-20 permission or Permit2 permission?
  • Does the tool include the relevant token or account type?

ERC-20 exposes a current allowance. A historical approval event records an earlier action; it may not describe the remaining permission after later spending or revocation.

Account for signatures

An unsubmitted signature may not appear as an onchain approval yet. ERC-2612 permits can later change allowance, and Permit2 has separate token and application authorization layers.

A scanner that lists only standard token allowances may therefore omit another form of authority without being wrong about the field it actually checks.

Verify important entries directly

Use the correct token or permission contract’s current state through a trusted explorer or official interface when a significant discrepancy remains. Confirm revocation receipts and refresh indexed results.

Do not connect to a tool from an unsolicited warning message solely because it promises a more complete scan. The scanner itself can request harmful approvals. Read every transaction it proposes, and never enter a recovery phrase to let it inspect public permission state.

Sources & verification (4)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. ERC-20: Token Standard

    Allowance, spender, transferFrom, metadata and approval event semantics.

    https://eips.ethereum.org/EIPS/eip-20
  2. ERC-2612: Permit Extension for EIP-20 Signed Approvals

    Signed approval fields, nonce, deadline, domain and permit submission.

    https://eips.ethereum.org/EIPS/eip-2612
  3. Permit2 Overview

    Token approval layer and distinction between SignatureTransfer and AllowanceTransfer.

    https://developers.uniswap.org/docs/protocols/permit2/overview
  4. How to revoke smart contract access to your crypto funds

    Revocation and disconnecting are distinct actions.

    https://ethereum.org/guides/how-to-revoke-token-access

Continue reading

How to revoke an unused swap allowance safely Can I revoke a permit signature that has not been used?