Wallet security
Disconnecting a wallet does not erase a token approval

At a glance
A website connection and an on-chain token allowance are different permissions. Disconnecting the site does not automatically revoke an ERC-20 allowance. Review the token, network and spender, and verify the result of any on-chain revocation.
On this page
Closing a browser tab can end your interaction with a service without removing the permissions you previously granted. For token approvals, the useful record is the allowance attached to a token and spender on the correct network.
Three things to keep separate
The ERC-20 standard defines approval and allowance for a spender. That authorization is not the same as a site's connection to the wallet interface. MetaMask's revocation guide explains why reviewing and revoking allowances is a separate on-chain action.
Your recovery credentials are a third category. They must not be supplied to a website to disconnect or inspect an approval. An allowance review is not an account-recovery process.
A permission ledger
Imagine a fictional token and a standard allowance that starts at 300 units. Assume the authorized spender consumes 80 and the token follows the ordinary decrementing behavior. The remainder is 220 units. Disconnecting the website does not turn that 220 into zero.
| Event | Illustrative allowance |
|---|---|
| Approve spender | 300 units |
| Spender uses 80 | 220 units |
| Disconnect website | Still 220 units |
| Successful confirmed revocation | 0 units |
This is not a model of every token, permit system or NFT approval. Some authorization mechanisms differ, so read the actual permission rather than assuming one screen covers everything.
Verify the object you are changing
Record network, token contract, spender address and allowance. A familiar application name alone does not identify the authorized contract. Review instructions through independently located official wallet documentation and inspect transaction details before signing.
Revocation can require gas and must be confirmed. It does not recover assets already transferred, invalidate every possible signature or repair a compromised recovery phrase. If the underlying keys are exposed, treat that as a different incident rather than relying solely on allowance cleanup.
A useful review habit
Keep an inventory after trying a new application: what permission was granted, why it was needed and whether it remains necessary. A smaller explicit allowance can limit that particular permission, but does not make an unsafe contract trustworthy. Do not accept a new unexplained approval merely because a page calls itself a revocation tool.
For gas reconciliation, see maximum budget versus actual fee. For account protection beyond allowances, use our security checklist.
CoinFom editorial note: research, writing, translation and review used AI assistance. No live transaction was performed for this article. Numerical examples are hypothetical and do not demonstrate returns. Sources checked September 26–27, 2026. Educational content, not personalized advice. See About CoinFom, our editorial and affiliate policy, or send a correction. CoinFom may earn referral commissions on other pages; this article contains no signup link.