imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Phishing & Scam Awareness

Learn look-alike domains, fake support, fake airdrops, malicious signatures and clipboard risk with practical security checks and on-chain verification guidance.

Core principles

Phishing pages often use look-alike domains, ads, private messages or forged QR codes. Prefer trusted bookmarks or known entry points for important actions.

  • Keep seed phrases and private keys under your control
  • Official support should not request recovery material
  • Verify address, network and amount before sending
  • Review DApp spender and permission scope
  • Use caution on public devices and networks

Risk scenarios

Phishing

Look-alike domains and fake support can redirect users to malicious requests.

Malicious approvals

A persistent token permission can remain active after a DApp session ends.

Device exposure

Screenshots, remote control and public devices can reveal sensitive material.

Transaction mistakes

Wrong network, address or amount can lead to irreversible outcomes.

How to respond

Some attacks seek a malicious message signature, token approval or contract transaction rather than recovery secrets. Review the requesting site, spender and permission scope before signing.

Malware can replace clipboard addresses, and remote-control tools can expose screens and wallet actions. Re-check pasted addresses and avoid sensitive actions while someone else controls the device.

Final check

For look-alike domains, fake support, fake airdrops, malicious signatures and clipboard risk, use a deliberate sequence: verify the entry point, confirm the network, check the address or contract, review the exact request, then submit. For asset movement, also verify the amount, fee and transaction hash. For DApps, distinguish connection, message signatures, transaction signatures and token approvals because they create different permissions.