2.Connect Your Wallet:Click "Connect Wallet" on the trusted tool. The site will pull data directly from the blockchain to show you every single smart contract that currently has permission to move your tokens.
3.Select the Correct Network:Approvals are chain-specific. If you were scammed on Arbitrum, you will not see the malicious contract if your wallet is connected to Ethereum Mainnet. Use the network dropdown on the tool to select the exact blockchain you were using when you made the mistake.
4.Identify the Malicious Approval:Sort by Newest.Sort your list of approvals by "Newest to Oldest." Look for the most recent contract you interacted with, or any contract showing an "Unlimited" spending allowance for your stablecoins (USDC/USDT) or native tokens.
5.Revoke the Permission:Click the "Revoke" button next to the suspicious contract. This will trigger a pop-up in your Web3 wallet (like MetaMask or Rabby). You must confirm this transaction and pay a small network gas fee to finalize the revocation on the blockchain.
6.Verify the Revocation:Wait a few seconds for the block to confirm, then refresh the revocation tool. Ensure the malicious contract has disappeared from your list of active approvals.
Crucial Warning: Revoking an approval only prevents future theft. It cannot recover funds that have already been drained. If your funds are already gone, or if you suspect your actual 12-word recovery phrase (seed phrase) was compromised, revoking is useless. You must immediately create an entirely new wallet and transfer any remaining assets to it.