A standard allowance is a spending permission, not a snapshot of the balance you held when approving. If permission remains, later deposits of the same token can become exposed to that spender.
Balance and permission are independent
ERC-20 separates balanceOf from allowance. An account can have zero balance and a large allowance. Zero balance prevents a current token pull, but it does not erase the permission.
Hypothetical example: you approve 1,000 units, spend 200 and later empty the account by transferring the remainder yourself. If 800 units of allowance remain, receiving 500 new units can make those units spendable through that permission, subject to the contract’s behavior.
Check the current implementation
Some tokens treat the maximum approval as effectively infinite and do not decrement it. OpenZeppelin documents this behavior in its ERC-20 implementation. Other token models can differ, so use current onchain allowance evidence.
The scope is still specific: this token contract, this account, this spender and this network. A similarly named token on another chain is not automatically covered by the same allowance.
Review dormant accounts before funding them
If you plan to reuse an old swap account, inspect its active permissions before sending substantial balances. An empty-wallet view can conceal meaningful future exposure.
Revocation can address a stale allowance. It cannot repair a leaked seed or invalidate every possible signed authorization. If the account has a suspicious history, identify the type of compromise before treating fresh funding as safe.
Sources & verification (3)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- ERC-20: Token Standard
Allowance, spender, transferFrom, metadata and approval event semantics.
https://eips.ethereum.org/EIPS/eip-20 - ERC20 | OpenZeppelin Docs
ERC-20 implementation behavior, zero-first approval compatibility and pausable token extension.
https://docs.openzeppelin.com/contracts/5.x/api/token/erc20 - What is a token approval?
Spender permissions, custom cap, future-balance exposure and malicious approvals.
https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-token-approval/