imtoken Knowledge Center
Device Security
The device environment matters. Public computers, remote-control tools, clipboard manipulation and untrusted networks can increase operational risk.
Protect secret credentials
Security starts by separating public information from secret credentials. An address can be shared for receiving assets; a seed phrase or private key should never be shared. In the context of Device Security, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
Recognize high-risk situations
Attackers often use urgency, imitation pages, fake support and deceptive approvals to make users skip verification. Slow down and check the domain and request details. In the context of Device Security, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
Device and network environment
Public computers, remote-control software, clipboard manipulation and untrusted networks widen the attack surface. High-value actions should be performed in a controlled device environment. In the context of Device Security, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
Final checks for transfers, signatures and approvals
Security starts by separating public information from secret credentials. An address can be shared for receiving assets; a seed phrase or private key should never be shared. In the context of Device Security, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
- Verify the active network and destination before confirming.
- Treat seed phrases and private keys as secret credentials.
- Review DApp, signature and approval requests independently.
