Marketplace approvals and drainer patterns in gaming
Before you can sell a game item on a marketplace, you sign an approval — a transaction that grants the marketplace’s contract permission to move items out of your wallet when a trade executes. That mechanism is how every game-asset marketplace works, and it’s also the surface drainer scams imitate. This page explains both sides.
What a marketplace approval actually is#
Game assets are NFTs held by your wallet address. A marketplace can’t move them without your consent — so the first time you list an item, the marketplace asks you to sign one of:
setApprovalForAll(marketplace_contract, true)— permission for that contract to transfer any item in the collection. Used by TokenTrove, Ronin Market, and most venues; it’s how listing can later happen gaslessly or server-side.approve(spender, tokenId)— the ERC-721 single-item version: permission for one specific asset only.- Off-chain listing signatures — messages (EIP-712 typed data) that authorise a trade at a given price without an on-chain transaction until a buyer fills it.
A legitimate approval is the engine of the marketplace. You grant it once, then can list items without re-approving.
Why approvals are the attack surface#
The same signature that enables a real sale enables theft when granted to the wrong contract:
- The fake-marketplace drainer. A clone of a real venue asks you to “start selling” — the approval goes to the attacker’s contract instead. Nothing appears on the real site; your items are movable by the attacker permanently.
- The “signed listing” drainer. Fake “sell your item for 2 ETH” prompts present an
eth_sign/EIP-712 message that is actually a buy-side signature or an order the attacker can execute to take your asset for near-zero. - The bundled-payload trick. A page requests two signatures back-to-back: one innocent-looking and one
setApprovalForAll. Speed and UI polish hide the second ask. - Old approvals as residue. Approvals never expire on their own. A grant to a contract that later gets exploited (or a marketplace that later proves malicious) remains a live drain path even if you haven’t touched the site in months.
How to tell a normal approval from a drainer#
| Normal marketplace flow | Drainer pattern |
|---|---|
| Reached by clicking “Sell” inside the verified marketplace UI | Reached from a link (DM, ad, comment, “rewards” page) |
| Approves a contract the marketplace itself operates | Approves a fresh, unlabelled, or mismatched contract |
| Request appears at the listing step, not at connect/login | Signature demanded just to “verify,” “claim,” or “view” |
Wallet shows setApprovalForAll to the known venue |
Wallet shows it to an unfamiliar address — or a blind eth_sign with no readable payload |
When in doubt: don’t sign. Check the contract address against the marketplace’s official documentation, or use the venue’s own UI entry points rather than links.
Living safely with approvals#
- Approve once, per collection, per real marketplace. Re-signing for the same venue on the same collection is a red flag.
- Keep a lean approval surface. Periodically audit your wallet’s active approvals and revoke ones you don’t use — especially to dead platforms. A dormant approval is dormant attack surface.
- Separate wallets by risk. Gaming wallet for play/trading; vault wallet for anything you care about. A drained gaming wallet should be an annoyance, not a loss.
- Prefer single-item approvals where offered. More signatures, less standing permission — worthwhile for high-value items.
- Treat a dead marketplace’s approval as a live risk. Shut-down platforms (see the status board) can’t protect their contract infrastructure — revoke leftover approvals to any dead venue.
The boundary note#
Generic approval mechanics, revocation walkthroughs, and wallet-security fundamentals are covered on NFTUniverse — this page is the game-asset-specific layer. Marketplace selection, fees, and the AU lens live on NFTMarketplace.
Sources#
- TokenTrove / Ronin Market / Pulse Market listing models — https://tokentrove.com, https://marketplace.roninchain.com, https://mythos.foundation (official, verified 2026-09-28)
- Approval-based drainer incidence in the gaming segment — ecosystem research ledger, category 9 records (verified 2026-09-28)