Consider a wallet that was once used for DeFi. Its USDT has been moved elsewhere, the old app is disconnected, and the address sits empty. Months later, its owner sends fresh USDT back to the same address on the same network.

That deposit can put money within reach of a permission granted long before it arrived. When the owner approved the app to spend USDT, the token contract recorded an allowance for that spender. The allowance and the wallet's balance are separate quantities. An ordinary transfer that empties the wallet doesn't, by itself, cancel the allowance.

If some permission remains, the approved contract may still be able to spend the newly deposited USDT, up to that remaining amount. This concerns that particular token and spender, not every asset in the wallet. It doesn't mean every old app will take the money; it means an empty balance didn't settle what the app was allowed to do.

MetaMask's distinction between disconnecting and revoking resolves the apparent contradiction. Disconnecting ends the site's connection to the wallet. Revoking changes the spending approval on the blockchain and costs a network fee. For this hypothetical wallet, revocation is the action that removes the spender's remaining permission. Emptying the wallet merely left it with nothing to spend at the time.

Source: https://support.metamask.io/more-web3/learn/how-to-revoke-smart-contract-allowances-token-approvals/
Image: AI-generated editorial illustration.