What a token approval actually is
Use a wallet with a website and you'll be asked to approve things. There are two kinds. They look almost the same in the popup, and the difference between them is most of the risk in everyday crypto.
A signature proves who you are. The site asks you to sign a message — some text and a random number. Nothing moves. Nothing is spent. It's showing ID.
An approval is a transaction. You're telling a token contract that some other address may move your tokens for you. Exchanges genuinely need this: the contract has to be able to take what you're selling.
Two things about approvals surprise people.
They last. An approval doesn't end when you close the tab or disconnect. It sits on the chain until you remove it, which could be years.
And they're often unlimited. Many sites ask for permission to move your whole balance of that token, now and in future, instead of just what you're trading. It's done so you're not asked again on every trade. It also means a contract that turns out to be flawed — or was malicious from the start — can take all of that token whenever it likes.
On a phone, in the moment, a signature request and an unlimited approval don't look very different. Both are a popup with a confirm button and text you didn't write.
That's why Aureus has no connect button. Not because approvals are bad — they're how the system works — but because we'd be teaching you to click through popups from us, then asking you to be careful about popups from everyone else.
This explains what things mean. It isn't investment advice, and nothing here says whether an asset is worth buying.