{"id":261,"date":"2026-08-22T12:01:23","date_gmt":"2026-08-22T16:01:23","guid":{"rendered":"https:\/\/dolanduck.io\/blog\/?p=261"},"modified":"2026-08-22T12:01:23","modified_gmt":"2026-08-22T16:01:23","slug":"revoke-token-approvals-solana","status":"publish","type":"post","link":"https:\/\/dolanduck.io\/blog\/revoke-token-approvals-solana\/","title":{"rendered":"How to Revoke Token Approvals and Delegates on Solana 2026"},"content":{"rendered":"\n<p>Revoking a token approval on Solana means removing a delegate \u2014 an address you previously authorised to move tokens from one of your token accounts. Solana&#8217;s model differs from Ethereum&#8217;s: instead of a blanket allowance for a contract across your whole wallet, each token account can name one delegate with an approved amount, and revoking clears that account&#8217;s delegate specifically. Checking and revoking is worth doing periodically, but it is important to understand the limit: on Solana the more common way wallets get emptied does not involve delegates at all.<\/p>\n\n\n<!--more-->\n\n\n<h2 class=\"wp-block-heading\">Key Facts<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>A delegate is set per token account, not per wallet, and each account can have at most one at a time.<\/li><li>The delegate can transfer up to the approved amount without any further signature from you.<\/li><li>Revoking is a single instruction that clears the delegate on that specific token account.<\/li><li>Approving a new delegate replaces the old one \u2014 there is no accumulating list.<\/li><li>A delegate cannot close your account or take your SOL, only move that token balance.<\/li><li>SetAuthority is the more dangerous instruction \u2014 it hands over ownership of the account itself.<\/li><li>Most Solana drains come from one malicious signature transferring everything immediately, not from a delegate waiting.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How Solana&#8217;s Model Differs From Ethereum&#8217;s<\/h2>\n\n\n\n<p>On Ethereum, approving a contract grants it an allowance for a token across your address, and those allowances stack up over years of DeFi use \u2014 hence the whole industry of approval-revoking tools. On Solana, because <a href=\"\/blog\/what-are-spl-tokens-solana-guide-2026\/\">each token balance lives in its own account<\/a>, a delegate is attached to that one account and there is only ever one. Approving a new delegate overwrites the previous one rather than adding to it.<\/p>\n\n\n\n<p>The practical effect is that Solana wallets do not accumulate a long tail of forgotten approvals the way Ethereum wallets do. The exposure is narrower and easier to audit \u2014 but it is also less familiar, so people who learned the habit on Ethereum sometimes assume revoking is the main defence here. It is not.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Three Levels of Authority<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th><\/th><th>Delegate<\/th><th>Account owner<\/th><th>Close authority<\/th><\/tr><\/thead><tbody><tr><td>Set by<\/td><td>Approve instruction<\/td><td>SetAuthority instruction<\/td><td>SetAuthority instruction<\/td><\/tr><tr><td>Can transfer tokens<\/td><td>Up to approved amount<\/td><td>Entire balance<\/td><td>No<\/td><\/tr><tr><td>Can close the account<\/td><td>No<\/td><td>Yes<\/td><td>Yes<\/td><\/tr><tr><td>Revocable by you<\/td><td>Yes, one instruction<\/td><td>No, once transferred<\/td><td>No, once transferred<\/td><\/tr><tr><td>Seen in drainer attacks<\/td><td>Sometimes<\/td><td>Occasionally, and worse<\/td><td>Occasionally<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>The fourth row is the one to internalise. A delegate is a permission you can withdraw. Ownership transferred through SetAuthority is not \u2014 once another address owns your token account, you cannot revoke anything, because the account is no longer yours to configure. Any transaction requesting SetAuthority on your accounts deserves to be rejected unless you know precisely why it is there.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Check and Revoke<\/h2>\n\n\n\n<p>Open your address on <a href=\"https:\/\/solscan.io\" rel=\"nofollow\">Solscan<\/a> and look through your token accounts \u2014 each one shows its delegate field, and a populated delegate on an account you did not intend to share is the thing you are looking for. Most wallets, including Gem Wallet, Phantom and Solflare, surface token approvals in a security or settings panel and let you revoke in one transaction. Each revocation costs a base fee and takes a slot like any other transaction.<\/p>\n\n\n\n<p>Do this after connecting to anything unfamiliar, and as routine maintenance every few months. Combine it with closing empty token accounts, since that both reclaims rent and removes accounts a stale delegate might sit on. Legitimate delegates do exist \u2014 some limit order and DCA systems on routers such as <a href=\"https:\/\/jup.ag\" rel=\"nofollow\">Jupiter<\/a> use them to execute on your behalf \u2014 so the goal is recognising which ones you authorised, not clearing everything reflexively.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Revoking Is Not the Main Defence<\/h2>\n\n\n\n<p>Here is the uncomfortable part. A Solana transaction can bundle instructions that transfer every token you hold and close the accounts, all executed the moment you sign. That attack does not set a delegate and wait \u2014 it takes everything immediately, and there is nothing left to revoke afterwards. Revoking protects against the slower pattern where an attacker plants a delegate for later use, which is real but far less common than the instant version.<\/p>\n\n\n\n<p>So treat revocation as hygiene rather than armour. The actual defence is reading transactions before signing, keeping risky activity in a separate address, and assuming any interface asking for a signature you cannot parse is hostile \u2014 the operating model behind <a href=\"\/blog\/burner-wallet-solana\/\">running a burner wallet<\/a> in the first place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Checking Delegates on a $DOLAN Account<\/h2>\n\n\n\n<p>DOLAN Duck ($DOLAN) is a standard SPL token with a fixed 98.3M supply held across roughly 10,700 accounts, and each of those is an ordinary token account with its own delegate field \u2014 nothing token-specific applies. If you hold a position, the check takes seconds: open the account on an explorer, confirm the delegate field is empty, and confirm the owner is still your address. The second half of that check matters more than the first and gets skipped more often, because a transferred owner is unrecoverable while a delegate is one transaction away from gone. Run both after any unfamiliar connection, alongside the wider routine in <a href=\"\/blog\/best-solana-wallet-memecoins-2026\/\">choosing and configuring a wallet properly<\/a>.<\/p>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1754643901\"><strong class=\"schema-faq-question\">What is a token delegate on Solana?<\/strong> <p class=\"schema-faq-answer\">A delegate is an address you authorise to move tokens from one specific token account, up to an approved amount, without needing another signature from you.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754643902\"><strong class=\"schema-faq-question\">How do I revoke a token approval on Solana?<\/strong> <p class=\"schema-faq-answer\">Open your token accounts on an explorer and read the delegate field on each, or use the approvals panel in your wallet. Revoking is a single instruction that clears the delegate on that account.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754643903\"><strong class=\"schema-faq-question\">How is this different from Ethereum approvals?<\/strong> <p class=\"schema-faq-answer\">Ethereum grants contract allowances that accumulate across your wallet over time. Solana attaches one delegate to each individual token account, and approving a new one overwrites the old, so nothing stacks up.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754643904\"><strong class=\"schema-faq-question\">Can a delegate close my account or take my SOL?<\/strong> <p class=\"schema-faq-answer\">No. A delegate can only transfer the token balance in that account. Closing the account or taking your SOL requires account ownership, which is a separate and more dangerous authority.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754643905\"><strong class=\"schema-faq-question\">What is SetAuthority and why is it dangerous?<\/strong> <p class=\"schema-faq-answer\">SetAuthority transfers ownership or close authority of a token account to another address. Unlike a delegate, it cannot be revoked afterwards, because the account is no longer yours to configure.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754643906\"><strong class=\"schema-faq-question\">Will revoking approvals protect me from a drainer?<\/strong> <p class=\"schema-faq-answer\">Not on its own. Most Solana drains happen in a single signed transaction that transfers everything immediately, leaving nothing to revoke. Revocation is maintenance, not protection.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754643907\"><strong class=\"schema-faq-question\">How often should I check approvals?<\/strong> <p class=\"schema-faq-answer\">After connecting to anything unfamiliar, and as routine maintenance every few months. Combining it with closing empty token accounts also reclaims the rent locked in them.<\/p> <\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Revoking a token approval on Solana means removing a delegate \u2014 an address you previously authorised to move tokens from one of your token accounts&#8230;.<\/p>\n","protected":false},"author":2,"featured_media":350,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-261","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain"],"_links":{"self":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts\/261","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/comments?post=261"}],"version-history":[{"count":1,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts\/261\/revisions"}],"predecessor-version":[{"id":427,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts\/261\/revisions\/427"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/media\/350"}],"wp:attachment":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/media?parent=261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/categories?post=261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/tags?post=261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}