Before approving an aggregator, verify the allowance spender for the exact chain and integration. The token contract, transaction entry point and authorized spender can be three different addresses.
Know which address means what
| Address | Role |
|---|---|
| Token contract | Stores the token balance and allowance. |
| Allowance spender | Receives authority to pull that token. |
| Swap entry point | Receives the execution transaction. |
0x’s contract documentation provides a concrete example: its approval target and execution entry point can differ, and it explicitly warns users not to grant allowances to Settler. A rule such as “approve whichever address the swap sends to” is therefore unsafe.
Verify from an independent official reference
Open the provider’s deployment documentation through a known genuine domain. Match the network, contract role and current version. Compare the full address with the spender shown in the wallet’s detailed approval request.
A block-explorer name tag is useful context, not a substitute for the deployment match. Similarly, a token address that matches the issuer does not validate the spender inside the approval.
If the application cannot explain a new spender or its documentation does not match, stop before signing. A recognizable logo and a previously successful swap do not resolve the discrepancy.
Limit the remaining exposure
After verifying identity, choose a cap consistent with the intended use. Identity verification and permission sizing solve different problems: an authentic contract can still carry implementation or upgrade risk. Keep the approval hash so you can later review or revoke the precise permission.
Sources & verification (3)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- Contracts | 0x Docs
Allowance targets differ from execution entry points; 0x warns against allowances to Settler.
https://docs.0x.org/docs/core-concepts/contracts - ERC-20: Token Standard
Allowance, spender, transferFrom, metadata and approval event semantics.
https://eips.ethereum.org/EIPS/eip-20 - What is a token approval?
Spender permissions, custom cap, future-balance exposure and malicious approvals.
https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-token-approval/