imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken

Device Security

Use core principles, risk scenarios, recognition methods and response steps to build repeatable security habits.

Server-rendered HTMLOn-chain verifiableSecurity-first education

Lock and update

Reliable screen locking and timely system updates are basic controls. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

In practice, combine interface information with data you can verify on-chain. If anything is unclear, stop before a high-value action and confirm the network, address, contract or transaction state.

Remote control

Remote access lets another person observe or influence wallet actions. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

In a multi-chain environment, the network name, native gas asset, block explorer and contract address create the decision context. Icons, symbols and screenshots are only supporting cues.

Public computers

Public devices are hard to audit for extensions, cached sessions and key logging. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

Seed phrases and private keys remain under user control, and official staff will never request them. Any website or person asking for recovery material or verification codes should not be trusted.

Clipboard and screenshots

Recheck copied addresses and never store a seed phrase in screenshots. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

When a third-party DApp, bridge or smart contract is involved, consider permission scope, contract risk, congestion and service dependencies. Confirmed on-chain transactions usually cannot be reversed by a wallet.

Extension management

Keep only necessary and trusted browser extensions. This topic should be understood through both user workflow and verifiable on-chain results. The wallet interface helps with context, but the network, address, contract and transaction state remain the source of truth.

After the action, keep the transaction hash and review confirmations to build independent verification habits. Revisit persistent connections and approvals when they are no longer needed.

Review after the action

After completing the task, compare the on-chain state with what you expected. Network, transaction hash, block height, confirmation count and approval status can reveal display delays, network mistakes or permissions that remain active longer than intended. Security is an ongoing review process, not a one-time setting.

Continue with imtoken

The download entry points to download.html. Back up first and verify the network before acting.

Download imtoken