imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Wallet Security Center

Learn seed phrases, private keys, approvals, devices, phishing and transfer checks with practical security checks and on-chain verification guidance.

Core principles

Wallet Security Center should be understood in the broader wallet and on-chain context. Identify the asset, network and controlling address, then determine whether the next step creates a connection, signature, approval or transaction. A clear model of seed phrases, private keys, approvals, devices, phishing and transfer checks makes it easier to separate interface messages from actual on-chain state.

  • Keep seed phrases and private keys under your control
  • Official support should not request recovery material
  • Verify address, network and amount before sending
  • Review DApp spender and permission scope
  • Use caution on public devices and networks

Risk scenarios

Phishing

Look-alike domains and fake support can redirect users to malicious requests.

Malicious approvals

A persistent token permission can remain active after a DApp session ends.

Device exposure

Screenshots, remote control and public devices can reveal sensitive material.

Transaction mistakes

Wrong network, address or amount can lead to irreversible outcomes.

How to respond

Common mistakes include using the wrong network, copying a bad address, ignoring token contracts, treating pending transactions as failures, or accepting an unclear approval. Troubleshoot seed phrases, private keys, approvals, devices, phishing and transfer checks with verifiable data such as transaction hashes, block heights, address history and contract addresses instead of relying only on interface messages.

Seed phrases and private keys should remain under the user’s control. Official support should not request them, and verification codes should never be shared. Third-party DApps, smart contracts and network services can introduce risk. Because confirmed transactions are usually not reversible by the wallet alone, pre-signing checks are essential.

Final check

For seed phrases, private keys, approvals, devices, phishing and transfer checks, use a deliberate sequence: verify the entry point, confirm the network, check the address or contract, review the exact request, then submit. For asset movement, also verify the amount, fee and transaction hash. For DApps, distinguish connection, message signatures, transaction signatures and token approvals because they create different permissions.