imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

Device Security

Device conditions affect wallet risk. Updates, screen locks, public computers, public Wi-Fi and remote-control software all deserve attention.

Key custody comes first

Seed phrases and private keys represent wallet control. Legitimate support should not ask for them, and they should never be submitted through chat, email, web forms, remote-access tools or screenshots. For Device Security, apply this principle to the specific fields and sequence described on this page.

Recognize common risk scenarios

Common risks include lookalike domains, fake support, fake airdrops, malicious signatures, clipboard address replacement and pressure to install remote-control software. Urgency and claims of risk-free returns are reasons to slow down and verify. For Device Security, apply this principle to the specific fields and sequence described on this page.

A practical verification method

When applying device security in a real task, confirm the active account and network first, then inspect the permission or transaction fields requested by the interface. Familiar-looking screens are not a reason to skip verification.

Check devices and network conditions

Keep operating systems and browsers updated, use a reliable screen lock and avoid handling wallets on public computers. On public Wi-Fi, do not relax domain and request checks simply because the connection appears to work. For Device Security, apply this principle to the specific fields and sequence described on this page.

Review signatures, approvals and transfers

Signatures, approvals and transfers are different operations. Read a signature, inspect the spender and allowance for an approval, and verify the address, network and amount before a transfer. On-chain transactions are usually not reversible by a wallet provider. For Device Security, apply this principle to the specific fields and sequence described on this page.

Important reminder

Keep your seed phrase and private key under your own control. imtoken support will not ask for them or for verification codes. Review the address, network, request details and permission scope before transferring, signing or approving. On-chain transactions are usually not reversible by a wallet provider. For Device Security, apply this principle to the specific fields and sequence described on this page.

Respond to suspicious activity methodically

If something looks wrong, stop signing and transferring, disconnect the suspicious site, review recent transactions and permissions, and reassess the account from a trusted device. Never reveal keys to someone claiming they can recover them for you. For Device Security, apply this principle to the specific fields and sequence described on this page.

Applying Device Security in a real workflow

The value of understanding updates, screen protection, networks, and remote access is not memorizing isolated terminology. It is building a repeatable decision process for each action. With Device Security, the visible button is only the start of an action; the actual outcome depends on the selected account, the active network, the destination address or contract, the permissions being requested, and the state eventually recorded on-chain. Define the outcome you expect before you approve the request shown on screen.

A useful review can be divided into four layers: keeping systems and browsers updated, using reliable device locks, avoiding key handling on public computers, and rejecting unsolicited remote-control requests. First confirm who or what the request is for. Next verify the network context. Then read the amount, fee, permission scope, or function parameters. Finally, after submission, compare the wallet record with a transaction hash or the appropriate block explorer. If any layer conflicts with what you intended to do, stop and re-check the source rather than trying a sequence of different confirmations.

A review habit worth keeping

For Device Security, proceed only when you can explain the important fields in your own words. An unfamiliar contract, unexpectedly broad approval, unexplained network switch, opaque signature, or any page asking for secret recovery material deserves additional scrutiny. A seed phrase or private key should remain under the user's control and should never be sent to another person. A DApp connection, message signature, token approval, and on-chain transaction are separate actions with separate consequences.

  • State the intended network, destination, and expected result before starting.
  • Before confirming, review the address, network, amount, fee, and permission scope that apply.
  • After submission, keep the public transaction hash or equivalent reference and verify it on the matching network.
  • When the task is complete, review connections and on-chain approvals that are no longer needed.

If a field in Device Security is not clear, learn what it represents before increasing value or permission scope. On-chain transactions generally cannot be reversed unilaterally by a wallet, and third-party DApps, bridges, and smart contracts introduce risks beyond the wallet interface. A deliberate sequence—understand, verify, then confirm—is more reliable than optimizing for speed.