imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken

Phishing & Scams

Use core principles, risk scenarios, recognition methods and response steps to build repeatable security habits.

Server-rendered HTMLOn-chain verifiableSecurity-first education

Urgency

Pressure language about expiring rewards or frozen assets is often used to bypass careful review. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

In practice, combine interface information with data you can verify on-chain. If anything is unclear, stop before a high-value action and confirm the network, address, contract or transaction state.

Lookalike domains

Similar domains, ads and cloned sites can mislead users. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

In a multi-chain environment, the network name, native gas asset, block explorer and contract address create the decision context. Icons, symbols and screenshots are only supporting cues.

Fake support

Official staff will not ask for recovery secrets, codes or remote access. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

Seed phrases and private keys remain under user control, and official staff will never request them. Any website or person asking for recovery material or verification codes should not be trusted.

Fake airdrops

Unknown airdrops or NFTs can lead to malicious signing and approvals. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

When a third-party DApp, bridge or smart contract is involved, consider permission scope, contract risk, congestion and service dependencies. Confirmed on-chain transactions usually cannot be reversed by a wallet.

Stop interaction

If a request looks suspicious, stop signing, approving and sending before verifying independently. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

After the action, keep the transaction hash and review confirmations to build independent verification habits. Revisit persistent connections and approvals when they are no longer needed.

Review after the action

After completing the task, compare the on-chain state with what you expected. Network, transaction hash, block height, confirmation count and approval status can reveal display delays, network mistakes or permissions that remain active longer than intended. Security is an ongoing review process, not a one-time setting.

Continue with imtoken

The download entry points to download.html. Back up first and verify the network before acting.

Download imtoken