{
  "object": "jepeta_content_article",
  "schemaVersion": "1.0.0",
  "id": "article.token-approval-risk-before-swap",
  "contentType": "security_intelligence",
  "title": "Token approval risk before a Base token swap",
  "slug": "token-approval-risk-before-swap",
  "category": "security",
  "intent": "Understand why token approvals deserve a separate security check before interacting with a Base token.",
  "directAnswer": "A token approval can grant a contract permission to move tokens, so checking the requested allowance is a distinct security step from checking the token itself. Jepeta's source audit combines Base application guidance with wallet approval guidance before directing readers to the scanner.",
  "sections": [
    {
      "heading": "Source audit",
      "paragraphs": [
        "Base security guidance tells application developers to minimize exposure of user funds and request only the amount needed for a transaction.",
        "MetaMask explains that token approvals let a dapp access and move approved tokens and that those allowances are distinct from simply connecting a wallet."
      ]
    },
    {
      "heading": "Security implication",
      "paragraphs": [
        "Ethereum.org recommends approving only what is needed or regularly revoking access that is no longer required.",
        "Allowance review is therefore a separate security control from checking token-contract risk signals before a swap."
      ]
    },
    {
      "heading": "Limits of this security finding",
      "paragraphs": [
        "This page separates documented permission mechanics from broader token and application risk. It does not infer that a contract is safe merely because one control passes."
      ]
    }
  ],
  "sources": [
    {
      "id": "base_security",
      "label": "Base security documentation",
      "url": "https://docs.base.org/specifications/security/avoid-malicious-flags",
      "sourceType": "primary",
      "publishedAt": null,
      "verifiedAt": "2026-10-06T13:00:26.371259Z"
    },
    {
      "id": "metamask_approvals",
      "label": "MetaMask token approval guidance",
      "url": "https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-token-approval/",
      "sourceType": "primary",
      "publishedAt": null,
      "verifiedAt": "2026-10-06T13:00:26.371259Z"
    },
    {
      "id": "ethereum_revoke",
      "label": "Ethereum.org token access revocation guide",
      "url": "https://ethereum.org/guides/how-to-revoke-token-access",
      "sourceType": "primary",
      "publishedAt": null,
      "verifiedAt": "2026-10-06T13:00:26.371259Z"
    }
  ],
  "sourceDates": [
    {
      "sourceId": "base_security",
      "publishedAt": null,
      "verifiedAt": "2026-10-06T13:00:26.371259Z"
    },
    {
      "sourceId": "metamask_approvals",
      "publishedAt": null,
      "verifiedAt": "2026-10-06T13:00:26.371259Z"
    },
    {
      "sourceId": "ethereum_revoke",
      "publishedAt": null,
      "verifiedAt": "2026-10-06T13:00:26.371259Z"
    }
  ],
  "originalEvidence": [
    {
      "type": "source_audit",
      "description": "Source audit of Base, MetaMask and Ethereum.org separates token-contract screening from the spender permissions granted by an approval.",
      "url": null,
      "observedAt": "2026-10-05T14:35:00Z"
    }
  ],
  "datePublished": "2026-10-06T11:45:00Z",
  "dateModified": "2026-10-06T13:00:26.371259Z",
  "reviewedAt": "2026-10-06T13:00:26.371259Z",
  "affiliate": {
    "enabled": false,
    "partnerId": null,
    "linkId": null,
    "disclosureRequired": false,
    "rel": null
  },
  "disclosure": null,
  "internalLinks": [
    "/articles/jepeta-security-evidence-audit/",
    "/#scanner",
    "/research/"
  ],
  "telegramCohort": {
    "surface": "article",
    "cohortId": "article"
  },
  "quality": {
    "decision": "publish",
    "citabilityScore": 100,
    "reviewedAt": "2026-10-06T13:00:26.371259Z",
    "policyVersion": "1.0.0"
  },
  "canonicalUrl": "https://jepeta.dev/articles/token-approval-risk-before-swap/",
  "jsonUrl": "https://jepeta.dev/articles/token-approval-risk-before-swap/index.json"
}
