imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken

Security

Wallet security begins with control of private keys, seed phrases, devices and permission boundaries. Legitimate support should never ask for a seed phrase, private key or verification code.

Legitimate support will not ask for a seed phrase, private key or verification code.
On this pageCore principles
Common risk scenarios
Pre-action checks
What to do after an incident
Action checklist

Core principles

For core principles, start by identifying the account, network and intended action. Wallet security begins with control of private keys, seed phrases, devices and permission boundaries. Legitimate support should never ask for a seed phrase, private key or verification code. Keep verifiable information available—such as the address, network name, transaction hash and approval target—instead of relying on vague interface messages.

Practical checks

On-chain activity is easier to understand when the wallet interface is separated from the underlying network state. A wallet organizes accounts, networks and transaction data, while the blockchain ultimately determines confirmation. If a balance, status or approval looks unusual, first verify the selected network, then review the address, transaction hash or contract information.

Seed phrases and private keys are credentials that remain under the user’s custody. imtoken staff will not ask for them, and they should never be sent to another person together with verification codes. Public devices, unknown networks and remote-control software introduce additional risk.

Common risk scenarios

For common risk scenarios, start by identifying the account, network and intended action. Wallet security begins with control of private keys, seed phrases, devices and permission boundaries. Legitimate support should never ask for a seed phrase, private key or verification code. Keep verifiable information available—such as the address, network name, transaction hash and approval target—instead of relying on vague interface messages.

Practical checks

Security is part of every step, not only incident response. For each transfer, signature or approval, identify the target, network, amount or permission scope. Treat unfamiliar domains, links and unexpected requests with caution, even when they appear inside a familiar workflow.

Networks can differ in fees, confirmation behavior, block explorers and asset rules. Similar-looking addresses do not prove that two networks are interchangeable. Before sending, verify the address, network and amount together and make sure the account has enough of the required gas asset.

Pre-action checks

For pre-action checks, start by identifying the account, network and intended action. Wallet security begins with control of private keys, seed phrases, devices and permission boundaries. Legitimate support should never ask for a seed phrase, private key or verification code. Keep verifiable information available—such as the address, network name, transaction hash and approval target—instead of relying on vague interface messages.

Practical checks

Seed phrases and private keys are credentials that remain under the user’s custody. imtoken staff will not ask for them, and they should never be sent to another person together with verification codes. Public devices, unknown networks and remote-control software introduce additional risk.

Third-party DApps and smart contracts can contain technical risks, malicious logic or misleading permission requests. Connecting a wallet does not mean every later prompt should be accepted. Each signature and approval should be reviewed on its own, and unused permissions should be revoked when appropriate.

What to do after an incident

For what to do after an incident, start by identifying the account, network and intended action. Wallet security begins with control of private keys, seed phrases, devices and permission boundaries. Legitimate support should never ask for a seed phrase, private key or verification code. Keep verifiable information available—such as the address, network name, transaction hash and approval target—instead of relying on vague interface messages.

Practical checks

Networks can differ in fees, confirmation behavior, block explorers and asset rules. Similar-looking addresses do not prove that two networks are interchangeable. Before sending, verify the address, network and amount together and make sure the account has enough of the required gas asset.

After an on-chain transaction is broadcast, a wallet provider generally cannot reverse it unilaterally. Confirmation should be checked against the relevant network. Congestion or inadequate fees can extend waiting times, so repeated duplicate actions should be avoided while a transaction is still pending.

Action checklist

  • Confirm the active network matches the intended network
  • Verify receiving or contract addresses carefully
  • Understand the actual meaning of each signature, approval or transaction
  • Never share a seed phrase, private key or verification code
  • Review and remove DApp connections or approvals that are no longer needed
On-chain transactions generally cannot be reversed unilaterally by a wallet provider. Third-party DApps, smart contracts, bridges and staking services can introduce technical or market risk.