jepeta.
Jepeta/Articles/security
security intelligence

Disconnecting a Wallet Is Not Revoking Token Access: The Exact Difference

Show why disconnecting a dapp does not cancel an ERC-20 spending allowance and how to verify both controls separately.

Direct answer

Disconnecting a wallet removes an application's current wallet connection permissions. Revoking a token allowance changes an onchain spending authorization for a specific token and spender. The actions are not interchangeable: a spender may retain allowance after you disconnect, and a revocation does not automatically sign you out of the website.

Two permissions, two different places

A wallet connection is usually an application/session permission: the site may request your account address and ask the wallet to present transactions for signing. Removing that connection changes what the site can request through the wallet interface. A token approval is a separate ERC-20 state recorded on a blockchain. The approved spender may be a router, vault or another contract. Disconnecting the visible session does not undo a previous blockchain transaction. MetaMask explicitly separates these actions.

Compare the actual effects

ActionWhere the change happensWhat it normally stopsWhat it does not prove
Disconnect a dappWallet connection/session settingsThe site's current wallet sessionPreviously granted token allowances are gone
Revoke allowanceOnchain token contract stateThe spender's permission to transfer that token under the allowanceThe website is trustworthy or a position has been closed
Move funds to a different walletOnchain wallet balancesLeaving those tokens in the old addressOld permissions on the old address have been erased

A wallet interface may give these controls similar names. Check which action actually produces a blockchain transaction and what address it modifies.

Example: a swap approval that outlives a visit

Imagine you approve a router to move a token, complete a swap and then disconnect the dapp. The site's connection may be gone, yet a nonzero token allowance can remain. A properly functioning spender still has the authorization recorded onchain. Ethereum.org explains that onchain allowances can persist long after an application session ends. This example illustrates a permission boundary; it is not a claim that a particular exchange or router is abusing that permission.

How to verify a disconnect

Open your wallet's connected-sites or permissions screen and remove the site's connection if you no longer use it. Confirm that the site cannot silently reconnect using the same wallet session. The details vary across MetaMask Extension, mobile wallets and hardware-wallet integrations. Avoid accepting a new permission request only to verify that the old one disappeared. Disconnecting is useful privacy and account-session hygiene, but it is not the onchain step.

How to verify an onchain revocation

Use an official allowance viewer or a carefully verified revocation tool on the correct network. Inspect the spender, token contract and allowance, not just a logo. If you revoke it, examine the transaction before signing, pay the required network fee, wait for confirmation, then refresh the allowance view. Ethereum.org's revocation guide describes this chain-specific workflow and explains why network selection matters. Revocation does not require exposing a seed phrase.

Mistakes worth avoiding

Do not equate 'not connected' with 'no active approvals'. Do not assume one approval tool covers every chain. Do not trust a dapp's name if its spender address does not match independently verified documentation. Do not assume revocation retroactively reverses transfers made before confirmation. Finally, do not confuse wallet permissions with token-level safety: even a perfectly revoked allowance says nothing about future liquidity, contract ownership or application security.

Next step

A useful habit is to perform two separate checks after experimenting with a DeFi app: remove any unwanted wallet connection and inspect standing token allowances on the correct network. Our permission hygiene checklist organizes these steps; the Jepeta scanner is a different tool for investigating token-level evidence. Neither is a safety guarantee.

Evidence and source-review method

  • structured comparison — Primary-source editorial comparison of documented security or import/tax procedures, including a task-oriented checklist and limits. No live wallet test, tax filing, or exchange API account verification is claimed. · evidence · observed Oct 9, 2026

Editorial transparency

This article was prepared with AI-assisted tools and an evidence-oriented source review. Citations and limitations are provided below. Documentation comparison is not a hands-on test; historical content is not automatically certified under the later independent editorial review process. Editorial standards and corrections.

Sources

Related Jepeta resources