Revoking a token approval on Solana means removing a delegate — an address you previously authorised to move tokens from one of your token accounts. Solana’s model differs from Ethereum’s: instead of a blanket allowance for a contract across your whole wallet, each token account can name one delegate with an approved amount, and revoking clears that account’s delegate specifically. Checking and revoking is worth doing periodically, but it is important to understand the limit: on Solana the more common way wallets get emptied does not involve delegates at all.
Key Facts
- A delegate is set per token account, not per wallet, and each account can have at most one at a time.
- The delegate can transfer up to the approved amount without any further signature from you.
- Revoking is a single instruction that clears the delegate on that specific token account.
- Approving a new delegate replaces the old one — there is no accumulating list.
- A delegate cannot close your account or take your SOL, only move that token balance.
- SetAuthority is the more dangerous instruction — it hands over ownership of the account itself.
- Most Solana drains come from one malicious signature transferring everything immediately, not from a delegate waiting.
How Solana’s Model Differs From Ethereum’s
On Ethereum, approving a contract grants it an allowance for a token across your address, and those allowances stack up over years of DeFi use — hence the whole industry of approval-revoking tools. On Solana, because each token balance lives in its own account, a delegate is attached to that one account and there is only ever one. Approving a new delegate overwrites the previous one rather than adding to it.
The practical effect is that Solana wallets do not accumulate a long tail of forgotten approvals the way Ethereum wallets do. The exposure is narrower and easier to audit — but it is also less familiar, so people who learned the habit on Ethereum sometimes assume revoking is the main defence here. It is not.
Three Levels of Authority
| Delegate | Account owner | Close authority | |
|---|---|---|---|
| Set by | Approve instruction | SetAuthority instruction | SetAuthority instruction |
| Can transfer tokens | Up to approved amount | Entire balance | No |
| Can close the account | No | Yes | Yes |
| Revocable by you | Yes, one instruction | No, once transferred | No, once transferred |
| Seen in drainer attacks | Sometimes | Occasionally, and worse | Occasionally |
The fourth row is the one to internalise. A delegate is a permission you can withdraw. Ownership transferred through SetAuthority is not — once another address owns your token account, you cannot revoke anything, because the account is no longer yours to configure. Any transaction requesting SetAuthority on your accounts deserves to be rejected unless you know precisely why it is there.
How to Check and Revoke
Open your address on Solscan and look through your token accounts — each one shows its delegate field, and a populated delegate on an account you did not intend to share is the thing you are looking for. Most wallets, including Gem Wallet, Phantom and Solflare, surface token approvals in a security or settings panel and let you revoke in one transaction. Each revocation costs a base fee and takes a slot like any other transaction.
Do this after connecting to anything unfamiliar, and as routine maintenance every few months. Combine it with closing empty token accounts, since that both reclaims rent and removes accounts a stale delegate might sit on. Legitimate delegates do exist — some limit order and DCA systems on routers such as Jupiter use them to execute on your behalf — so the goal is recognising which ones you authorised, not clearing everything reflexively.
Why Revoking Is Not the Main Defence
Here is the uncomfortable part. A Solana transaction can bundle instructions that transfer every token you hold and close the accounts, all executed the moment you sign. That attack does not set a delegate and wait — it takes everything immediately, and there is nothing left to revoke afterwards. Revoking protects against the slower pattern where an attacker plants a delegate for later use, which is real but far less common than the instant version.
So treat revocation as hygiene rather than armour. The actual defence is reading transactions before signing, keeping risky activity in a separate address, and assuming any interface asking for a signature you cannot parse is hostile — the operating model behind running a burner wallet in the first place.
Checking Delegates on a $DOLAN Account
DOLAN Duck ($DOLAN) is a standard SPL token with a fixed 98.3M supply held across roughly 10,700 accounts, and each of those is an ordinary token account with its own delegate field — nothing token-specific applies. If you hold a position, the check takes seconds: open the account on an explorer, confirm the delegate field is empty, and confirm the owner is still your address. The second half of that check matters more than the first and gets skipped more often, because a transferred owner is unrecoverable while a delegate is one transaction away from gone. Run both after any unfamiliar connection, alongside the wider routine in choosing and configuring a wallet properly.
A delegate is an address you authorise to move tokens from one specific token account, up to an approved amount, without needing another signature from you.
Open your token accounts on an explorer and read the delegate field on each, or use the approvals panel in your wallet. Revoking is a single instruction that clears the delegate on that account.
Ethereum grants contract allowances that accumulate across your wallet over time. Solana attaches one delegate to each individual token account, and approving a new one overwrites the old, so nothing stacks up.
No. A delegate can only transfer the token balance in that account. Closing the account or taking your SOL requires account ownership, which is a separate and more dangerous authority.
SetAuthority transfers ownership or close authority of a token account to another address. Unlike a delegate, it cannot be revoked afterwards, because the account is no longer yours to configure.
Not on its own. Most Solana drains happen in a single signed transaction that transfers everything immediately, leaving nothing to revoke. Revocation is maintenance, not protection.
After connecting to anything unfamiliar, and as routine maintenance every few months. Combining it with closing empty token accounts also reclaims the rent locked in them.