Key custody comes first
Seed phrases and private keys represent wallet control. Legitimate support should not ask for them, and they should never be submitted through chat, email, web forms, remote-access tools or screenshots.
Recognize common risk scenarios
Common risks include lookalike domains, fake support, fake airdrops, malicious signatures, clipboard address replacement and pressure to install remote-control software. Urgency and claims of risk-free returns are reasons to slow down and verify.
A practical verification method
When applying approval security in a real task, confirm the active account and network first, then inspect the permission or transaction fields requested by the interface. Familiar-looking screens are not a reason to skip verification.
Check devices and network conditions
Keep operating systems and browsers updated, use a reliable screen lock and avoid handling wallets on public computers. On public Wi-Fi, do not relax domain and request checks simply because the connection appears to work.
Review signatures, approvals and transfers
Signatures, approvals and transfers are different operations. Read a signature, inspect the spender and allowance for an approval, and verify the address, network and amount before a transfer. On-chain transactions are usually not reversible by a wallet provider.
Keep your seed phrase and private key under your own control. imtoken support will not ask for them or for verification codes. Review the address, network, request details and permission scope before transferring, signing or approving. On-chain transactions are usually not reversible by a wallet provider.
Respond to suspicious activity methodically
If something looks wrong, stop signing and transferring, disconnect the suspicious site, review recent transactions and permissions, and reassess the account from a trusted device. Never reveal keys to someone claiming they can recover them for you.
