imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken

Security

Build a practical security framework around seed phrases, private keys, approvals, phishing, devices, and transaction checks.

不分享秘密

Never share secrets

逐次确认

Review each request

先核对再提交

Verify before submission

Seed phrases and private keys control the wallet

These secrets are not ordinary login passwords. Anyone who obtains them may gain control, so they should never be shared through chat, email, forms, or remote-control software. imtoken personnel will not ask for them. Prefer offline backup and protect that backup from loss, damage, and unwanted viewing. For Security, convert this principle into a repeatable check: identify the action, verify the network and counterparty, and review the important fields again before signing or submitting. This is more reliable than trusting colors, icons, or familiarity alone. If the result does not match your expectation, stop, keep the transaction hash, contract address, or network details, and verify them through a trusted source. Do not skip checks because a page creates urgency or promises a reward.

Read signatures and approvals before confirming

A signature can prove account control, authorize a message, or be connected to a transaction or approval. The fact that a prompt appears inside a wallet does not make the underlying request trustworthy. Compare it with the domain, network, contract, and action you intentionally started. For Security, convert this principle into a repeatable check: identify the action, verify the network and counterparty, and review the important fields again before signing or submitting. This is more reliable than trusting colors, icons, or familiarity alone. If the result does not match your expectation, stop, keep the transaction hash, contract address, or network details, and verify them through a trusted source. Do not skip checks because a page creates urgency or promises a reward.

Protect the device environment

Keep the operating system, browser, and wallet software updated, use a strong device lock, and avoid importing a wallet on shared computers. Public networks do not automatically compromise a wallet, but unfamiliar environments increase the chance of phishing, interception, or unwanted observation during sensitive actions. For Security, convert this principle into a repeatable check: identify the action, verify the network and counterparty, and review the important fields again before signing or submitting. This is more reliable than trusting colors, icons, or familiarity alone. If the result does not match your expectation, stop, keep the transaction hash, contract address, or network details, and verify them through a trusted source. Do not skip checks because a page creates urgency or promises a reward.

Operational checklist

  • Verify the domain or entry point
  • Confirm the active network
  • Review addresses or contract targets
  • Check amount, fee, or permission scope
  • Keep the transaction hash after broadcast

Prevention matters because transactions are hard to reverse

Verify address, network, and amount before signing. After submission, keep the transaction hash and inspect it with a trusted explorer. On-chain transactions generally cannot be unilaterally reversed by a wallet, so the best point to stop an error is before approval, not after broadcast. For Security, convert this principle into a repeatable check: identify the action, verify the network and counterparty, and review the important fields again before signing or submitting. This is more reliable than trusting colors, icons, or familiarity alone. If the result does not match your expectation, stop, keep the transaction hash, contract address, or network details, and verify them through a trusted source. Do not skip checks because a page creates urgency or promises a reward.

Turn knowledge into a repeatable checklist

The goal of learning Security is not to collect terminology but to make actions verifiable. Keep a personal checklist for trusted entry points, the active network, addresses or contracts, amounts or permission scope, and post-transaction verification. Reject requests you cannot explain. imtoken will never ask you to enter a seed phrase, private key, recovery phrase, or verification code on a webpage, and on-chain transactions generally cannot be unilaterally reversed by a wallet.

Continue with a verified workflow

Review the network, address, amount, and request details before every important action.

Download imtoken