imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken

Device Security

Protect the environment where the wallet runs through updates, app provenance, screen locks, network hygiene and remote-control awareness.

Verify the networkReview the requestKeep verifiable records
Check 1

Wallet security also depends on the device

In practice, Wallet security also depends on the device connects to several steps before and after the action itself. Device security includes system updates, screen locks, application provenance, malware protection and physical access control. A wallet cannot replace device-level protection. If the device shows suspicious popups, unknown software or remote-control activity, stop sensitive actions first.

A mobile wallet brings network management, balances, transaction records and DApp interaction onto a personal device. That convenience also makes device hygiene important: system updates, screen locks, app provenance and malware exposure all matter. Higher-value or higher-permission actions deserve an extra independent check, such as a second device, trusted bookmark or small test transaction.

A private key directly represents signing authority and should never be treated as a routine identity check. If a webpage, chat window, remote-support tool or supposed sync service asks for it, stop and independently verify the source. Seed phrases, private keys and verification codes are never required as troubleshooting material and should not be shared with anyone.

Before you confirm

  • Verify the network, address or contract source relevant to wallet security also depends on the device.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.
Check 2

Install and update only from trusted sources

Breaking Install and update only from trusted sources into smaller decisions is more reliable than accepting a single page-level conclusion. Device security includes system updates, screen locks, application provenance, malware protection and physical access control. A wallet cannot replace device-level protection. If the device shows suspicious popups, unknown software or remote-control activity, stop sensitive actions first.

Phishing pages often rely on lookalike domains, search ads, direct messages or fake promotions. Use a trusted entry point and verify the domain. A familiar logo, polished design or urgent warning does not make a site legitimate. Before confirming, compare the active network, target and intended outcome together. If one of them does not match, stop and recheck rather than continuing out of habit.

Fake support commonly arrives through unsolicited messages, remote-control requests, recovery-phrase demands or instructions to install unknown software. A legitimate security process does not require sending seed phrases, private keys or verification codes to anyone. Verify contact through an independent official entry point. A useful final test is to ask four questions: which network am I on, who am I interacting with, what permission am I granting, and what on-chain result should I expect?

Make the checks repeatable

  • Verify the network, address or contract source relevant to install and update only from trusted sources.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.
Check 3

Limits of public networks and shared computers

The easiest way to understand Limits of public networks and shared computers is to place it inside a real wallet workflow. Public Wi-Fi and shared computers increase exposure to session theft, malicious software and account compromise. For wallet login, signing or backup work, prefer devices and networks you control and avoid leaving sensitive sessions on shared machines.

Web connections usually create a session between the browser and the wallet. A site receives the account information the user allows and can then request signatures or transactions. Connecting does not hand over the private key, and it does not make every later request trustworthy. Order matters: verify the source and network first, then the address or contract, and only then review amounts, fees, signatures or permissions.

A seed phrase can usually recreate wallet control on another device, so exposure can compromise the account. Keep it offline, do not send it to support, avoid long-term photo storage, and verify the word order and legibility after creating the backup. Seed phrases, private keys and verification codes are never required as troubleshooting material and should not be shared with anyone.

Practical checks

  • Verify the network, address or contract source relevant to limits of public networks and shared computers.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.
Check 4

Clipboard and remote-control risk

With Clipboard and remote-control risk, one common mistake is treating interface text as the final on-chain truth. Clipboard malware can replace long addresses in ways that are hard to notice. After copying an address, compare the beginning, ending and key characters again. For important transfers, consider an address book, small test or second-device verification.

Remote-control tools can expose the screen, keyboard, mouse and clipboard to another person. Do not continue wallet, backup or signing tasks under remote direction from an unknown party, and never reveal seed phrases, private keys or verification codes. Higher-value or higher-permission actions deserve an extra independent check, such as a second device, trusted bookmark or small test transaction.

An address identifies an on-chain account or contract. Before sending assets, verify both the destination network and the address, including the beginning, ending and trusted source. Recheck anything copied from chat or the clipboard in case it was altered. A useful final test is to ask four questions: which network am I on, who am I interacting with, what permission am I granting, and what on-chain result should I expect?

What is easy to miss

  • Verify the network, address or contract source relevant to clipboard and remote-control risk.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.

Security statement

Seed phrases and private keys remain under the user’s control. Official personnel will not ask for them or for verification codes; on-chain transactions generally cannot be reversed by a wallet alone; third-party DApps and smart contracts may carry risk.

imtoken

Ready to get started?

The download entry always goes through the dedicated download page. Keep verifying networks, addresses and request details before acting.

Download imtoken