imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Home / Security
imtoken

Security

Security: practical guidance with network, transaction, permission and security checks.

Core security principles

Security concepts

For Security, this section connects Security concepts with Security workflow. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Security workflow

In practical use, Security verification should not be evaluated separately from Security risk. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Security management as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

Common risk scenarios

Security workflow

For Security, this section connects Security workflow with Security verification. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Security verification

In practical use, Security risk should not be evaluated separately from Security management. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Security concepts as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

How to identify and respond

Security verification

For Security, this section connects Security verification with Security risk. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Security risk

In practical use, Security management should not be evaluated separately from Security concepts. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Security workflow as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

Everyday security checks

Security risk

For Security, this section connects Security risk with Security management. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Security management

In practical use, Security concepts should not be evaluated separately from Security workflow. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Security verification as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

Risk note

Third-party DApps and smart contracts can introduce risk. Review permissions and remove approvals you no longer need.