Categories: Glossary

Infinite Approval

Understanding Infinite Approval

Infinite approval is a concept in smart contract programming that is often viewed as problematic. It involves a smart contract requiring authorization to access an unlimited number of tokens from a user’s wallet, rather than just the necessary amount.

An instance of a smart contract programmed with infinite approval can be found in the decentralized exchange Bancor. When a user initially interacts with the system, they are required to authorize the smart contract to withdraw an unlimited number of tokens from their wallet.

Bancor’s smart contracts had a vulnerability that could have potentially allowed a hacker to steal all the tokens authorized by the user. Fortunately, the developers of Bancor identified this vulnerability before any malicious actors could exploit it. They promptly made adjustments to their systems so that only the required number of tokens would be requested for approval. As a precautionary measure, the developers temporarily assumed control of user funds and later returned them to prevent any potential hacks.

Following the controversy surrounding Bancor, it was discovered that infinite approval is a common practice among decentralized application programmers. Research conducted by a researcher at crypto wallet ZenGo revealed that popular decentralized applications such as Compound, Uniswap, bZX, Aave, Kyber, and dYdX all incorporate infinite or significantly large approvals.

For instance, a liquidity provider may contribute $5,000 worth of Ether and $5,000 worth of the USD-pegged decentralized stablecoin DAI to a liquidity pool. This enables trading between the two assets. Whenever a trade occurs on the ETH/DAI pair, the liquidity provider receives compensation for their contribution to the pool.

Coincu

Share
Published by
Coincu

Recent Posts

The Next Generation Crypto Coin!

The pursuit of the next generation crypto coin is captivating investors and enthusiasts alike. As…

46 mins ago

Market Overview (May 13 – May 19): Unicoin SEC Registration and the Rise of Meme Coins

Discover the latest crypto news: SEC registrations, Central Bank approvals, market trends, and more. Stay…

4 hours ago

Magic Eden’s Coinbase Account Used to Bear “Significant” Dust Fees

The platform shifted small transaction fees to Magic Eden's Coinbase account, making Coinbase handle the…

5 hours ago

Spot Ethereum ETF 19b-4 Filings Expected To Be Approved This Week

The SEC is expected to decide this week on the approval of a spot Ethereum…

6 hours ago

AI.Society and Paal AI Announce Strategic Partnership to Enhance User Engagement with Custom AI Solutions

AI.Society is excited to announce a new strategic partnership with Paal AI, a pioneer in…

6 hours ago

Tornado Cash Ruling Casts Dark Shadow Over Market!

Alexey Pertsev, a developer of the coin-mixing protocol Tornado Cash, has sent shockwaves through the…

18 hours ago

This website uses cookies.