A detailed post explains how crypto wallet approvals—permissions granted to smart contracts to move tokens and NFTs—pose ongoing security risks because they rarely expire and persist even after apps shut down. The author documents multiple real incidents across DeFi and NFT platforms where attackers exploited forgotten approvals to drain millions in assets, and advises users to regularly revoke these permissions.
A Twitter discussion thread documents major smart contract exploits and approval vulnerabilities in crypto. Examples include the $351.6M Bitget exchange breach, Magic Eden NFT marketplace drains via forgotten approvals, and multiple DeFi protocol hacks (SushiSwap, Li.Fi, BarnBridge) where users lost funds through infinite token approvals that were never revoked.
A discussion about the $351M Bitget security breach highlights that crypto exchange hacks aren't just about stolen private keys—they involve compromising entire infrastructure stacks including approval systems, multisigs, and backend services. The thread warns that malicious actors can exploit trusted components across any exchange, custodian, or protocol, and emphasizes the need to revoke forgotten token approvals that persist even after apps shut down.
Crest is a macOS notch app that displays Claude Code and Codex approval prompts directly in the MacBook notch, allowing users to tap Allow or Deny without switching to the terminal. It uses Claude Code's hook system to intercept permission requests and keeps the prompt visible across all apps and desktops.