imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken

Home / Device Security

imtoken

Device Security

Device Security is organized around real wallet actions, network differences and security checks so each step, permission and on-chain result can be understood.

Device Security

Device as entry point

Device as entry point is a distinct part of understanding Device Security. First identify the network, account and action involved, then compare what the wallet displays with what you actually intend to do. Familiarity with a workflow is not a reason to skip verification for transfers, contract calls or approvals.

Use a repeatable review sequence for device as entry point: network and address first, then asset or contract, then request details, value and fees, and finally the on-chain result after submission. Cancel requests with unclear fields, unfamiliar contracts, unexpectedly broad allowances or pressure to act quickly.

Similar address formats do not make networks interoperable. Before transferring, re-check the network, amount, gas and destination. For important actions, keep a public address or transaction hash and verify the on-chain result with a block explorer. Stop when interface data conflicts with chain data.

Practical checks

  • Confirm the active network and account for device as entry point
  • Verify the destination, contract or requested action
  • Never share a seed phrase, private key or verification code
  • Use a transaction hash to verify the result on-chain

Public environments

Public environments is a distinct part of understanding Device Security. First identify the network, account and action involved, then compare what the wallet displays with what you actually intend to do. Familiarity with a workflow is not a reason to skip verification for transfers, contract calls or approvals.

Use a repeatable review sequence for public environments: network and address first, then asset or contract, then request details, value and fees, and finally the on-chain result after submission. Cancel requests with unclear fields, unfamiliar contracts, unexpectedly broad allowances or pressure to act quickly.

After connecting to a DApp, inspect every signature, transaction and token approval independently; disconnecting does not necessarily revoke an on-chain allowance. Similar address formats do not make networks interoperable. Before transferring, re-check the network, amount, gas and destination.

Practical checks

  • Confirm the active network and account for public environments
  • Verify the destination, contract or requested action
  • Never share a seed phrase, private key or verification code
  • Use a transaction hash to verify the result on-chain

Extension sources

Extension sources is a distinct part of understanding Device Security. First identify the network, account and action involved, then compare what the wallet displays with what you actually intend to do. Familiarity with a workflow is not a reason to skip verification for transfers, contract calls or approvals.

Use a repeatable review sequence for extension sources: network and address first, then asset or contract, then request details, value and fees, and finally the on-chain result after submission. Cancel requests with unclear fields, unfamiliar contracts, unexpectedly broad allowances or pressure to act quickly.

Security is a continuing routine: offline backups, trusted devices, fewer unnecessary approvals, caution on public networks and skepticism toward unexpected requests. After connecting to a DApp, inspect every signature, transaction and token approval independently; disconnecting does not necessarily revoke an on-chain allowance.

Practical checks

  • Confirm the active network and account for extension sources
  • Verify the destination, contract or requested action
  • Never share a seed phrase, private key or verification code
  • Use a transaction hash to verify the result on-chain

Remote and clipboard risks

Remote and clipboard risks is a distinct part of understanding Device Security. First identify the network, account and action involved, then compare what the wallet displays with what you actually intend to do. Familiarity with a workflow is not a reason to skip verification for transfers, contract calls or approvals.

Use a repeatable review sequence for remote and clipboard risks: network and address first, then asset or contract, then request details, value and fees, and finally the on-chain result after submission. Cancel requests with unclear fields, unfamiliar contracts, unexpectedly broad allowances or pressure to act quickly.

Review the active network, account and target together rather than relying on a page label or icon. Security is a continuing routine: offline backups, trusted devices, fewer unnecessary approvals, caution on public networks and skepticism toward unexpected requests.

Practical checks

  • Confirm the active network and account for remote and clipboard risks
  • Verify the destination, contract or requested action
  • Never share a seed phrase, private key or verification code
  • Use a transaction hash to verify the result on-chain
Seed phrases and private keys remain under user control; imtoken will never ask for them. On-chain transactions generally cannot be reversed unilaterally by a wallet.

Start with a clear verification workflow

After downloading, complete backup and network checks before transfers, signatures or approvals.

Download imtoken