imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Security center

Phishing & Scams

A useful way to approach Phishing & Scams is to ask three questions: what object is involved, what will the request change, and where can the result be verified? Phishing sites often use look-alike domains or paid search placement. Fake support accounts may initiate private chats and ask for secrets. Fake airdrops use “free” assets to push wallet connections and signatures. The sections below connect those ideas to account, network, contract, and permission context so that similar-looking information is not mistaken for identical on-chain state.

phishing sites often use look-alike domains or paid search placement

For Phishing & Scams, seed phrases and private keys remain under the user’s control, and imtoken personnel will not ask for a seed phrase, private key, or verification code. Before transferring, signing, or approving, review the address, network, contract target, amount, and permission scope. On-chain transactions generally cannot be reversed by a wallet alone, and third-party DApps or smart contracts can introduce additional risk. Stop and verify with public information whenever the request does not match the expected action.

On this pageCore principle: Phishing sites often use look-alike domains or paid search placementCommon risk scenarios: Fake airdrops use “free” assets to push wallet connections and signaturesHow to recognize the issue: Remote-control software can expose and operate the deviceWhat to do next: Social-media display names are easy to impersonateBuild a repeatable check: A site asking for a seed phrase or private key should be abandoned immediately

Core principle: Phishing sites often use look-alike domains or paid search placement

Focus on fake support accounts may initiate private chats and ask for secrets

First, in Phishing & Scams, Core principle: Phishing sites often use look-alike domains or paid search placement works best as a repeatable security rule, not as a one-time setting. Phishing sites often use look-alike domains or paid search placement. Fake support accounts may initiate private chats and ask for secrets. In a Phishing & Scams scenario, the practical response is to do not let a familiar label replace a technical check. A familiar interface, a rushed message, a supposed support agent, or an urgent promotion should never lower the standard for checking the domain, network, target, and permission being requested. If any of those details cannot be explained, stopping is safer than trying to discover the answer by signing first.

First follow-up in Phishing & Scams: Focus on fake support accounts may initiate private chats and ask for secrets can be turned into a concrete review sequence. Check the domain, address, network, contract target, and permission scope before acting, then compare the expected result with the state that is actually recorded afterward. Fake airdrops use “free” assets to push wallet connections and signatures. Countdowns and urgency are used to reduce review time. It is also important to manage long-lived permissions separately from one-time transactions. Troubleshooting can rely on public addresses, networks, transaction hashes, and contract records; a seed phrase, private key, or verification code is not troubleshooting data and should never be sent through chat, remote-control software, or an unfamiliar form.

  • Confirm phishing sites often use look-alike domains or paid search placement.
  • Check how fake support accounts may initiate private chats and ask for secrets affects the current request.
  • Use fake airdrops use “free” assets to push wallet connections and signatures as a separate verification point.

Common risk scenarios: Fake airdrops use “free” assets to push wallet connections and signatures

Focus on countdowns and urgency are used to reduce review time

Second, in Phishing & Scams, Common risk scenarios: Fake airdrops use “free” assets to push wallet connections and signatures works best as a repeatable security rule, not as a one-time setting. Fake airdrops use “free” assets to push wallet connections and signatures. Countdowns and urgency are used to reduce review time. In a Phishing & Scams scenario, the practical response is to stop when two pieces of context disagree. A familiar interface, a rushed message, a supposed support agent, or an urgent promotion should never lower the standard for checking the domain, network, target, and permission being requested. If any of those details cannot be explained, stopping is safer than trying to discover the answer by signing first.

Second follow-up in Phishing & Scams: Focus on countdowns and urgency are used to reduce review time can be turned into a concrete review sequence. Check the domain, address, network, contract target, and permission scope before acting, then compare the expected result with the state that is actually recorded afterward. Remote-control software can expose and operate the device. QR codes and shortened links can hide the real destination. It is also important to be especially careful with assumptions that arise from similar-looking networks. Troubleshooting can rely on public addresses, networks, transaction hashes, and contract records; a seed phrase, private key, or verification code is not troubleshooting data and should never be sent through chat, remote-control software, or an unfamiliar form.

  • Confirm fake airdrops use “free” assets to push wallet connections and signatures.
  • Check how countdowns and urgency are used to reduce review time affects the current request.
  • Use remote-control software can expose and operate the device as a separate verification point.

How to recognize the issue: Remote-control software can expose and operate the device

Focus on QR codes and shortened links can hide the real destination

Third, in Phishing & Scams, How to recognize the issue: Remote-control software can expose and operate the device works best as a repeatable security rule, not as a one-time setting. Remote-control software can expose and operate the device. QR codes and shortened links can hide the real destination. In a Phishing & Scams scenario, the practical response is to record the state before and after the action. A familiar interface, a rushed message, a supposed support agent, or an urgent promotion should never lower the standard for checking the domain, network, target, and permission being requested. If any of those details cannot be explained, stopping is safer than trying to discover the answer by signing first.

Third follow-up in Phishing & Scams: Focus on QR codes and shortened links can hide the real destination can be turned into a concrete review sequence. Check the domain, address, network, contract target, and permission scope before acting, then compare the expected result with the state that is actually recorded afterward. Social-media display names are easy to impersonate. Knowing a public transaction hash does not prove someone is official support. It is also important to distinguish a waiting state from a failed state. Troubleshooting can rely on public addresses, networks, transaction hashes, and contract records; a seed phrase, private key, or verification code is not troubleshooting data and should never be sent through chat, remote-control software, or an unfamiliar form.

  • Confirm remote-control software can expose and operate the device.
  • Check how QR codes and shortened links can hide the real destination affects the current request.
  • Use social-media display names are easy to impersonate as a separate verification point.

What to do next: Social-media display names are easy to impersonate

Focus on knowing a public transaction hash does not prove someone is official support

Fourth, in Phishing & Scams, What to do next: Social-media display names are easy to impersonate works best as a repeatable security rule, not as a one-time setting. Social-media display names are easy to impersonate. Knowing a public transaction hash does not prove someone is official support. In a Phishing & Scams scenario, the practical response is to treat network context as a prerequisite for every step. A familiar interface, a rushed message, a supposed support agent, or an urgent promotion should never lower the standard for checking the domain, network, target, and permission being requested. If any of those details cannot be explained, stopping is safer than trying to discover the answer by signing first.

Fourth follow-up in Phishing & Scams: Focus on knowing a public transaction hash does not prove someone is official support can be turned into a concrete review sequence. Check the domain, address, network, contract target, and permission scope before acting, then compare the expected result with the state that is actually recorded afterward. A site asking for a seed phrase or private key should be abandoned immediately. When something looks wrong, return through a trusted official entry point instead of continuing through chat links. It is also important to perform an independent review after submission. Troubleshooting can rely on public addresses, networks, transaction hashes, and contract records; a seed phrase, private key, or verification code is not troubleshooting data and should never be sent through chat, remote-control software, or an unfamiliar form.

  • Confirm social-media display names are easy to impersonate.
  • Check how knowing a public transaction hash does not prove someone is official support affects the current request.
  • Use a site asking for a seed phrase or private key should be abandoned immediately as a separate verification point.

Build a repeatable check: A site asking for a seed phrase or private key should be abandoned immediately

Focus on when something looks wrong, return through a trusted official entry point instead of continuing through chat links

Fifth, in Phishing & Scams, Build a repeatable check: A site asking for a seed phrase or private key should be abandoned immediately works best as a repeatable security rule, not as a one-time setting. A site asking for a seed phrase or private key should be abandoned immediately. When something looks wrong, return through a trusted official entry point instead of continuing through chat links. In a Phishing & Scams scenario, the practical response is to avoid repeated submissions when the current state is unclear. A familiar interface, a rushed message, a supposed support agent, or an urgent promotion should never lower the standard for checking the domain, network, target, and permission being requested. If any of those details cannot be explained, stopping is safer than trying to discover the answer by signing first.

Fifth follow-up in Phishing & Scams: Focus on when something looks wrong, return through a trusted official entry point instead of continuing through chat links can be turned into a concrete review sequence. Check the domain, address, network, contract target, and permission scope before acting, then compare the expected result with the state that is actually recorded afterward. Phishing sites often use look-alike domains or paid search placement. Fake support accounts may initiate private chats and ask for secrets. It is also important to separate interface cues from verifiable chain state. Troubleshooting can rely on public addresses, networks, transaction hashes, and contract records; a seed phrase, private key, or verification code is not troubleshooting data and should never be sent through chat, remote-control software, or an unfamiliar form.

  • Confirm a site asking for a seed phrase or private key should be abandoned immediately.
  • Check how when something looks wrong, return through a trusted official entry point instead of continuing through chat links affects the current request.
  • Use phishing sites often use look-alike domains or paid search placement as a separate verification point.

Practical checklist

  • Review phishing sites often use look-alike domains or paid search placement.
  • Review fake airdrops use “free” assets to push wallet connections and signatures.
  • Review remote-control software can expose and operate the device.
  • Review social-media display names are easy to impersonate.
  • Review a site asking for a seed phrase or private key should be abandoned immediately.