imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken Knowledge Center

Phishing & Scam Awareness

Fake support, fake airdrops, lookalike domains and deceptive signing flows often use urgency to make users skip verification.

Illustration about offline private-key protection
01

Protect secret credentials

Security starts by separating public information from secret credentials. An address can be shared for receiving assets; a seed phrase or private key should never be shared. In the context of Phishing & Scam Awareness, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.

A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.

02

Recognize high-risk situations

Attackers often use urgency, imitation pages, fake support and deceptive approvals to make users skip verification. Slow down and check the domain and request details. In the context of Phishing & Scam Awareness, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.

A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.

03

Device and network environment

Public computers, remote-control software, clipboard manipulation and untrusted networks widen the attack surface. High-value actions should be performed in a controlled device environment. In the context of Phishing & Scam Awareness, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.

A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.

04

Final checks for transfers, signatures and approvals

Security starts by separating public information from secret credentials. An address can be shared for receiving assets; a seed phrase or private key should never be shared. In the context of Phishing & Scam Awareness, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.

A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.

  • Verify the active network and destination before confirming.
  • Treat seed phrases and private keys as secret credentials.
  • Review DApp, signature and approval requests independently.