imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken Knowledge Center

Security Center

Build security habits around recovery secrets, devices, networks, signatures, approvals, and transfers.

offline private key storage

Protect recovery secrets first

Build security habits around recovery secrets, devices, networks, signatures, approvals, and transfers. A seed phrase or private key can authorize account control from another device, so these items deserve the highest level of protection. They should not be treated like ordinary passwords that can simply be reset by a support team.

imtoken staff will not ask for a seed phrase, private key, or verification code. Avoid screenshots, chat tools, email, and online forms for recovery information, and reject requests from anyone claiming that sharing a secret is required for support.

Treat devices and networks as part of the security boundary

Public Wi-Fi, shared computers, remote-control software, malicious browser extensions, and clipboard replacement can all affect the final wallet action. Sensitive operations are easier to reason about on a device and network environment you control.

For “Security Center”, verify pasted addresses, inspect the domain before a DApp session, and stop if the browser begins redirecting unexpectedly. Environment-level attacks can alter information before the final confirmation screen is shown.

Pre-sign checks matter more than post-transaction recovery

On-chain transactions generally cannot be unilaterally reversed by a wallet. Review the address, network, asset, amount, gas, contract, spender, and signature details before confirming. A small test transfer can reduce operational mistakes but does not remove contract or market risk.

Connection, signing, approval, and transfer are distinct actions. Disconnecting a site does not revoke an existing on-chain allowance, and revoking an allowance does not reverse an already confirmed transfer.

  • Check the active network
  • Verify address, contract, or approval target
  • Review amount, fees, and request details
  • Keep the transaction hash when relevant
  • Reject requests you cannot explain

Respond according to the incident type

If you only connected to a suspicious site without signing, disconnect and inspect later requests. If an approval was created, evaluate revocation on that network. If a recovery secret was exposed, changing an app password usually does not change the on-chain key.

For “Security Center”, protect remaining assets and recovery information first, then inspect the chain record. Do not continue sharing screens, codes, or secrets with an unsolicited person claiming to be support.

Security reminder

Keep your seed phrase and private key under your own control. imtoken staff will not ask for them. Review addresses, networks, contracts, signatures, and approvals before confirming.