Swap security

Stolen seed or malicious approval: why the response differs

Choose the right response by distinguishing stolen signing control from a malicious token permission.

A malicious approval delegates a specific kind of spending authority. A leaked private key or recovery phrase gives away signing control. Revoking an allowance can address the first problem while leaving the second completely unresolved.

Look at the evidence

Review unexpected transactions, their sender, called contracts and token movements. If you entered a seed into a website or installed a wallet that captured it, treat that secret as compromised even if only one theft is visible.

A transfer through an approved spender can occur without a new owner-signed transaction. That pattern can suggest approval abuse, but an unfamiliar transfer alone does not establish the entire cause. MetaMask’s unauthorized-transaction guidance recommends investigating the activity and possible compromise route.

Response to a malicious approval

Identify the exact chain, token and spender. Revoke the relevant permission through a verified interface and confirm the result. Check for other approvals or signatures granted during the same interaction. A pending revocation can still race with use of the permission.

Response to exposed signing secrets

The attacker can create new transactions and permissions. Changing the wallet’s local password or removing one approval does not change the blockchain keys.

Plan protection of remaining assets using authentic tools and a clean environment. A newly generated wallet must use a new secret; another account derived from the leaked phrase is not a clean destination. Consider all accounts and chains controlled by that phrase.

Watch for automatic sweeping

If native gas disappears immediately after deposit, stop repeatedly funding the account. A sweeper can take each new deposit before you use it. Obtain reputable specialist help rather than trying random rescue scripts or disclosing secrets again.

Keep public transaction evidence for reporting. Recovery of already transferred assets is a separate question from preventing further loss, and neither type of compromise justifies trusting guaranteed-recovery offers.

Sources & verification (4)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. I’ve been hacked or scammed

    Investigate unauthorized transactions, compromised secrets and remaining approvals; avoid funding suspected sweepers.

    https://support.metamask.io/stay-safe/protect-yourself/ive-been-hacked-scammed-unauthorized-transactions-on-my-account
  2. What to do if you have a sweeper bot on your wallet

    Compromised keys, automated balance draining and risk of further gas funding.

    https://support.metamask.io/stay-safe/protect-yourself/fighting-back-against-sweeper-bots/
  3. ERC-20: Token Standard

    Allowance, spender, transferFrom, metadata and approval event semantics.

    https://eips.ethereum.org/EIPS/eip-20
  4. Ethereum security and scam prevention

    Secret protection, phishing, address checks and public-key custody hygiene.

    https://ethereum.org/security/

Continue reading

Gas disappears immediately after funding a wallet: suspect a sweeper How to revoke an unused swap allowance safely