imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

Signature Requests

A signature may represent login, consent to a message or an on-chain transaction. Identify the type before deciding whether it matches your intent.

Verify the DApp entry point

Before opening a DApp, verify the domain and why you are there. Search ads, unsolicited messages and urgent promotions can lead to lookalike sites. A wallet connection only establishes limited account interaction; it does not validate later requests.

Understand signature types

Wallets can show message signatures, login signatures, transaction signatures or structured-data requests. Identify the request type first, then review the site, account, network, amount, contract and visible fields against your intended action.

A practical verification method

When applying signature requests in a real task, confirm the active account and network first, then inspect the permission or transaction fields requested by the interface. Familiar-looking screens are not a reason to skip verification.

Review token approval scope

A token approval gives a contract permission to use assets within a stated scope. Review the spender, allowance, network and whether an unlimited approval is truly necessary. Consider revoking permissions that are no longer needed.

Set boundaries for contract interaction

Smart contracts execute deployed code and can depend on external systems or market conditions. A wallet can display and submit requests, but it cannot determine whether a contract is safe or guarantee that an on-chain action can be reversed.

Important reminder

Keep your seed phrase and private key under your own control. imtoken support will not ask for them or for verification codes. Review the address, network, request details and permission scope before transferring, signing or approving. On-chain transactions are usually not reversible by a wallet provider.

Clean up connections and permissions

After using a DApp, disconnect sessions you no longer need and review historical approvals separately. Disconnecting a site does not necessarily revoke token permissions, so connection management and approval management are different tasks.