imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Home / Phishing & Scams
imtoken

Phishing & Scams

Phishing & Scams: practical guidance with network, transaction, permission and security checks.

Core security principles

Phishing concepts

For Phishing & Scams, this section connects Phishing concepts with Phishing workflow. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Phishing workflow

In practical use, Phishing verification should not be evaluated separately from Phishing risk. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Phishing management as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

Common risk scenarios

Phishing workflow

For Phishing & Scams, this section connects Phishing workflow with Phishing verification. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Phishing verification

In practical use, Phishing risk should not be evaluated separately from Phishing management. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Phishing concepts as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

How to identify and respond

Phishing verification

For Phishing & Scams, this section connects Phishing verification with Phishing risk. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Phishing risk

In practical use, Phishing management should not be evaluated separately from Phishing concepts. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Phishing workflow as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

Everyday security checks

Phishing risk

For Phishing & Scams, this section connects Phishing risk with Phishing management. Security is not a single feature; it is a set of habits that reduce exposure of recovery data, unnecessary approvals and incorrect transfers. Seed phrases and private keys remain under the user’s control, and official staff should never ask for them.

Phishing management

In practical use, Phishing concepts should not be evaluated separately from Phishing workflow. Be cautious with urgency, reward promises, fake airdrops, fake support and websites that ask you to import a wallet. Even legitimate requests should clearly identify the account, network, contract or signature context.

Treat Phishing verification as part of a repeatable review routine. Public computers, untrusted Wi-Fi, remote-control sessions and unknown software can increase risk. Important actions are better performed on trusted devices and networks. This helps turn visible information into verified information.

Risk note

Third-party DApps and smart contracts can introduce risk. Review permissions and remove approvals you no longer need.