imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken

FAQ

Answer common questions across wallets, networks, gas, transactions, DApps, approvals, security, Ethereum, proof of stake and validators.

Verify the networkReview the requestKeep verifiable records
Services & information

Answer common questions across wallets, networks, gas, transactions, DApps, approvals, security, Ethereum, proof of stake and validators.

01

Wallets and recovery credentials

In practice, Wallets and recovery credentials connects to several steps before and after the action itself. A useful FAQ resolves common misconceptions such as whether connection equals approval, whether gas indicates safety, or whether a delayed transaction should simply be resent. Answers should provide a practical verification path without asking for sensitive credentials.

A seed phrase can usually recreate wallet control on another device, so exposure can compromise the account. Keep it offline, do not send it to support, avoid long-term photo storage, and verify the word order and legibility after creating the backup. Higher-value or higher-permission actions deserve an extra independent check, such as a second device, trusted bookmark or small test transaction.

A private key directly represents signing authority and should never be treated as a routine identity check. If a webpage, chat window, remote-support tool or supposed sync service asks for it, stop and independently verify the source. Seed phrases, private keys and verification codes are never required as troubleshooting material and should not be shared with anyone.

Before you confirm

  • Verify the network, address or contract source relevant to wallets and recovery credentials.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.
02

Networks, gas and transaction state

Breaking Networks, gas and transaction state into smaller decisions is more reliable than accepting a single page-level conclusion. The same-looking address format can exist on different networks, while balances, gas assets, contracts and transaction histories remain separate. Choose the network based on where the asset actually exists and what the recipient supports, not just the token name shown in the interface.

Gas is the execution cost charged by the network for transactions or contract calls. It varies with network rules, congestion and operation complexity. Gas is not a fixed wallet price and does not indicate whether a request is safe; review the amount, network and request details as well. Before confirming, compare the active network, target and intended outcome together. If one of them does not match, stop and recheck rather than continuing out of habit.

A transaction hash is one of the main identifiers for locating an on-chain transaction. Use it with the correct network explorer to check broadcast status, block inclusion, execution result and fees. When a transfer is delayed, verify the hash before deciding whether to try again. A useful final test is to ask four questions: which network am I on, who am I interacting with, what permission am I granting, and what on-chain result should I expect?

Make the checks repeatable

  • Verify the network, address or contract source relevant to networks, gas and transaction state.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.
03

DApps, signatures and approvals

The easiest way to understand DApps, signatures and approvals is to place it inside a real wallet workflow. A DApp connection usually begins by requesting an account address or session, then may ask for signatures, transactions or approvals. Connecting is not the same as revealing a private key, but users should still verify the domain, session and network and disconnect when finished.

A signature proves that an account approved a message or transaction. Some message signatures do not transfer funds directly but can still authorize login or later actions. Before signing, review the recognizable domain, target, amount, permissions and any expiry. Order matters: verify the source and network first, then the address or contract, and only then review amounts, fees, signatures or permissions.

A token approval allows a contract to spend a token under defined conditions. Excessive allowance or approval to the wrong contract increases exposure. Verify the spender, token, amount and purpose, and periodically revoke permissions that are no longer needed. Seed phrases, private keys and verification codes are never required as troubleshooting material and should not be shared with anyone.

Practical checks

  • Verify the network, address or contract source relevant to dapps, signatures and approvals.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.
04

Ethereum, PoS and validators

With Ethereum, PoS and validators, one common mistake is treating interface text as the final on-chain truth. Ethereum uses proof of stake, with validators participating in proposing, attesting and finalizing the network by staking ETH. Before staking, understand validator operation, reward formation, withdrawals and exits instead of focusing on a single yield figure.

Validators need to remain correctly operated and follow protocol rules. Downtime can reduce rewards, while certain serious faults can trigger penalties. Solo operation, hosted services and liquid-staking models have different control and risk profiles and should be evaluated separately. Higher-value or higher-permission actions deserve an extra independent check, such as a second device, trusted bookmark or small test transaction.

Staking rewards are influenced by protocol issuance, network activity and validator performance, so they change with network conditions. They are not a fixed annual return or a guarantee. Consider fees, waiting periods, penalties and asset-price volatility as part of the decision. A useful final test is to ask four questions: which network am I on, who am I interacting with, what permission am I granting, and what on-chain result should I expect?

What is easy to miss

  • Verify the network, address or contract source relevant to ethereum, pos and validators.
  • Confirm that the request matches the intended action instead of relying on a familiar label.
  • Keep public identifiers such as transaction hashes for verification while keeping private credentials under your own control.

Common questions

What is the difference between a seed phrase and a private key?

A seed phrase commonly restores a set of accounts, while a private key directly controls signing for a specific account. Both are highly sensitive and should never be sent to another person or entered on an unfamiliar website.

Can official support recover a lost seed phrase?

No. A legitimate service should not hold the user’s seed phrase or private key, so it cannot recover those credentials on the user’s behalf. Create and verify an offline backup when the wallet is created.

Why do I need to confirm the network when receiving assets?

The same address format can exist across different networks while balances and histories remain separate. Sender and recipient need to use a compatible target network.

Is gas charged by the wallet?

Gas is generally the network execution cost for a transaction or contract call. It changes with network rules and congestion and is not a fixed price the wallet can guarantee.

What is a transaction hash used for?

The transaction hash lets you inspect broadcast status, block inclusion, execution result and fees on the correct explorer. It is one of the most useful public identifiers for troubleshooting.

Should I send again if a transfer is taking a long time?

Not immediately. Verify the network, transaction hash and block status first so you can tell whether the transfer failed, is still pending or the interface is simply delayed.

Does connecting to a DApp give the website my private key?

A normal connection should not expose the private key, but the DApp can later request signatures, transactions or approvals. Each of those actions still needs separate review.

Is a message signature safe if it does not use gas?

Not necessarily. A message signature can authorize login or protocol actions even without an on-chain fee. Review the domain, content, target and expiry before signing.

Are token approval and token transfer the same thing?

No. An approval usually gives a contract permission to spend a token within a defined allowance, while an actual transfer may happen later as a separate action.

Does disconnecting a DApp revoke approvals?

Usually not. Disconnecting ends the session, while an approval already stored on-chain normally requires a separate on-chain revocation transaction.

Why do EVM networks use similar-looking addresses?

EVM networks can share address and contract conventions while still having different chain IDs, gas assets, RPC endpoints and deployments. Similar addresses do not make them the same chain.

How is Layer 2 related to the base layer?

Layer 2 processes more activity away from the base layer and connects results back through its own design. Bridging, withdrawals and waiting periods depend on the specific system.

How can I recognize a phishing site?

Verify the domain and source, and be cautious with search ads, direct-message links and urgency. Stop immediately if a page asks for a seed phrase, private key or verification code.

Is it safe to use a wallet on public Wi-Fi?

Sensitive actions are better performed on devices and networks you control. Public networks and shared computers increase exposure to session theft, malware and remote interference.

Are Ethereum staking rewards fixed?

No. Rewards change with protocol rules, network activity and validator performance and do not represent a guaranteed return or principal protection.

Can a validator exit instantly?

Not always. Exits and withdrawals can depend on network queues and processing stages, so waiting time can vary with network conditions.

Can validators be penalized?

Yes. Proof-of-stake protocols use rewards and penalties to encourage correct operation, with different consequences for downtime and more serious faults.

What should I provide to support for a transaction issue?

The network name, transaction hash and public address are usually enough to verify public on-chain state. Do not provide a seed phrase, private key or verification code.

imtoken

Ready to get started?

The download entry always goes through the dedicated download page. Keep verifying networks, addresses and request details before acting.

Download imtoken