imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Seed Phrase & Private Keys

Learn wallet control, secret material, offline backup and recovery with practical security checks and on-chain verification guidance.

Core principles

Private keys authorize blockchain actions, while seed phrases commonly restore a set of derived keys. Anyone who obtains this secret material may gain control of the corresponding assets.

  • Keep seed phrases and private keys under your control
  • Official support should not request recovery material
  • Verify address, network and amount before sending
  • Review DApp spender and permission scope
  • Use caution on public devices and networks

Risk scenarios

Phishing

Look-alike domains and fake support can redirect users to malicious requests.

Malicious approvals

A persistent token permission can remain active after a DApp session ends.

Device exposure

Screenshots, remote control and public devices can reveal sensitive material.

Transaction mistakes

Wrong network, address or amount can lead to irreversible outcomes.

How to respond

Official support should never ask for a seed phrase or private key. Requests to verify, synchronize, unlock or recover a wallet by entering secret material into a website should be treated as high risk.

Recovery should be performed only in a trusted wallet on a controlled device, not during remote-control or screen-sharing sessions.

Final check

For wallet control, secret material, offline backup and recovery, use a deliberate sequence: verify the entry point, confirm the network, check the address or contract, review the exact request, then submit. For asset movement, also verify the amount, fee and transaction hash. For DApps, distinguish connection, message signatures, transaction signatures and token approvals because they create different permissions.