imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Home/Device Security | imtoken

imtoken knowledge & product center

Device Security

Reduce device risk through updates, network hygiene, clipboard checks, remote-access caution, and account separation.

Device Security

Security is not an absolute guarantee. A stronger approach is to reduce secret exposure, limit permissions, and repeat critical checks before confirmation.

device securitypublic networksclipboard risk
01

Start with non-negotiable security principles

Device Security is easier to use when device security and public networks are understood in the same operational context. Wallet safety depends on more than a password; system updates, malware, screen sharing, browser extensions, and local file protection all matter. Public Wi-Fi and shared networks add environmental uncertainty. Even with encrypted connections, device state, captive portals, and observation risks still matter. Putting these concepts together is more useful than memorizing vocabulary without knowing when a check matters.

Do not treat a familiar interface as proof that a request is trustworthy. Around device security and public networks, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • Before important actions, disable unnecessary remote-control or sharing tools and keep the operating system and browser current.
  • Prefer a trusted device and network for high-value actions and minimize scope when using a public environment.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
02

Recognize common risk scenarios

Device Security is easier to use when clipboard risk and remote access are understood in the same operational context. Malware can monitor or replace addresses in the clipboard, so copy-and-paste is not a substitute for final address verification. Remote-control software can expose the screen, inputs, and clicks to another party. Avoid letting an unknown person control a device during key, signature, or transfer operations. In practice, the useful habit is to match what the interface shows against the network, address, and actual request details.

Do not treat a familiar interface as proof that a request is trustworthy. Around clipboard risk and remote access, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • After pasting an address, recheck its leading and trailing characters and do not rely on clipboard history for important transfers.
  • If supposed support asks you to install a remote-access tool, stop the session and verify the source independently.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
03

What to do when something looks wrong

Device Security is easier to use when private key and address are understood in the same operational context. A private key directly controls the signing authority of an on-chain account. Anyone who obtains it may be able to produce valid signatures for that account. An address identifies an on-chain account or contract. Address formats can look similar across networks, so appearance alone is not enough to confirm the destination network. If two information sources disagree, stop before confirming and compare details that can be independently verified.

Do not treat a familiar interface as proof that a request is trustworthy. Around private key and address, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • A private key is not a support credential, reward claim code, or website identity check; stop immediately if one is requested.
  • Recheck the leading and trailing characters, destination network, and asset type; a small test transfer can reduce uncertainty for important transactions.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
04

Turn security into a repeatable habit

Device Security is easier to use when device security and public networks are understood in the same operational context. Wallet safety depends on more than a password; system updates, malware, screen sharing, browser extensions, and local file protection all matter. Public Wi-Fi and shared networks add environmental uncertainty. Even with encrypted connections, device state, captive portals, and observation risks still matter. These situations are rarely improved by clicking faster; separate the object, permission, and expected result instead.

Do not treat a familiar interface as proof that a request is trustworthy. Around device security and public networks, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • Before important actions, disable unnecessary remote-control or sharing tools and keep the operating system and browser current.
  • Prefer a trusted device and network for high-value actions and minimize scope when using a public environment.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
Security reminder

Keep seed phrases and private keys under your own control. Do not send them to anyone. Review the address, network, amount, signature text, and approval scope before confirming. Third-party DApps and smart contracts can introduce independent risk.