Skip to content

03 · Approvals ​

Approvals outlive the dapp that asked for them. Unlimited allowances to unknown contracts are what drainers live on.

Three passes ​

  1. Known pairs. 30 major BNB Chain tokens × 21 known spenders (PancakeSwap routers, Uniswap Universal Router and V4 PositionManager, Permit2, 1inch, OpenOcean, ParaSwap, KyberSwap, 0x, OKX, Odos, LI.FI, Socket, Seaport…) through allowance(owner, spender), batched.
  2. Permit2. allowance(owner, token, spender) on the Permit2 contract for the same tokens and the main spenders, with the expiry.
  3. Event scan. Optional: Approval and ApprovalForAll events where you are the owner, over the last ~1 or ~5 days of blocks, fetched in 5 000-block chunks (public RPC limit). Every candidate pair is then re-read with allowance() or isApprovedForAll() so only active allowances are listed. If the RPC refuses a range, the result says partial.

Risk per row ​

RiskMeaning
revokespender on a blocklist, or a plain wallet, or unlimited allowance to an unverified contract
warnlimited allowance to an unverified contract, or unlimited allowance to a known router
oklimited allowance to a known or verified contract

Revoke ​

Each row has a revoke button. It builds approve(spender, 0), setApprovalForAll(operator, false) or Permit2 approve(token, spender, 0, 0) and asks your browser wallet to sign it on BNB Chain. Routers need re-approval the next time you trade, which is the point.

Holder depth ​

Holding 1 M GRUB pre-selects the 5-day scan in the depth menu (you can still pick any depth). Nothing else changes: the tool is the same for everyone.

Grub · @grubonchain on X · open tools, no account · contracts unaudited · the official $GRUB address is published on the Contracts page first, anything before that is a scam.