imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken

Phishing & Scams

Phishing and scams often use lookalike domains, fake support, airdrop bait and urgency to push users into revealing credentials or signing risky requests.

Verify the networkReview the requestKeep verifiable records
Check 1

Spot lookalike entry points

Spot lookalike entry points is a practical part of understanding Phishing & Scams. Phishing and scams often use lookalike domains, fake support, airdrop bait and urgency to push users into revealing credentials or signing risky requests. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

A useful way to think about Spot lookalike entry points within Phishing & Scams is to separate what the interface displays from what the blockchain records. The wallet organizes information and submits requests, while the target network records the resulting state. Addresses, networks, contracts and transaction hashes are therefore important verification points.

For Spot lookalike entry points, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with spot lookalike entry points
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone
Check 2

Fake support & airdrops

Fake support & airdrops is a practical part of understanding Phishing & Scams. Phishing and scams often use lookalike domains, fake support, airdrop bait and urgency to push users into revealing credentials or signing risky requests. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

The risky part of Fake support & airdrops within Phishing & Scams is often the surrounding context rather than the button itself: which network is active, which site initiated the request, what permission is being granted, and whether the amount and fee make sense. Turning those checks into a routine is more reliable than reacting to prompts one by one.

For Fake support & airdrops, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with fake support & airdrops
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone
Check 3

Verify before signing

Verify before signing is a practical part of understanding Phishing & Scams. Phishing and scams often use lookalike domains, fake support, airdrop bait and urgency to push users into revealing credentials or signing risky requests. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

imtoken guidance focuses on information you can verify. When something is unclear, do not rely on a single line in a pop-up. Check the address, network, contract, transaction history and explorer data where relevant, then decide whether the action matches your intent.

For Verify before signing, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with verify before signing
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone
Check 4

When something looks wrong

When something looks wrong is a practical part of understanding Phishing & Scams. Phishing and scams often use lookalike domains, fake support, airdrop bait and urgency to push users into revealing credentials or signing risky requests. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

When something looks wrong within Phishing & Scams is not an isolated feature. In practice it is shaped by network state, account permissions, transaction parameters and user decisions. Understanding those relationships first makes similar-looking screens and labels much less confusing.

For When something looks wrong, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with when something looks wrong
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone

Security statement

Seed phrases and private keys remain under the user’s control. Official personnel will not ask for them or for verification codes; on-chain transactions generally cannot be reversed by a wallet alone; third-party DApps and smart contracts may carry risk.

imtoken

Ready to get started?

The download entry always goes through the dedicated download page. Keep verifying networks, addresses and request details before acting.

Download imtoken