imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Home/Seed Phrase & Private Keys | imtoken

imtoken knowledge & product center

Seed Phrase & Private Keys

Clarify control, backup, exposure risks, and response principles for seed phrases and private keys.

Seed Phrase & Private Keys

Security is not an absolute guarantee. A stronger approach is to reduce secret exposure, limit permissions, and repeat critical checks before confirmation.

seed phraseprivate keyoffline backup
01

Start with non-negotiable security principles

Seed Phrase & Private Keys is easier to use when seed phrase and private key are understood in the same operational context. A seed phrase can commonly restore a set of wallet accounts, making it more sensitive than an ordinary login password. If exposed, another party may be able to restore the wallet elsewhere. A private key directly controls the signing authority of an on-chain account. Anyone who obtains it may be able to produce valid signatures for that account. In practice, the useful habit is to match what the interface shows against the network, address, and actual request details.

Do not treat a familiar interface as proof that a request is trustworthy. Around seed phrase and private key, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • Prefer offline backup, avoid screenshots and messaging apps, and never hand it to someone claiming to be support.
  • A private key is not a support credential, reward claim code, or website identity check; stop immediately if one is requested.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
02

Recognize common risk scenarios

Seed Phrase & Private Keys is easier to use when offline backup and device security are understood in the same operational context. Offline backup reduces the chance that recovery material is exposed through cloud sync, chat history, screenshots, or remote-control environments. Wallet safety depends on more than a password; system updates, malware, screen sharing, browser extensions, and local file protection all matter. If two information sources disagree, stop before confirming and compare details that can be independently verified.

Do not treat a familiar interface as proof that a request is trustworthy. Around offline backup and device security, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • After backing up, confirm the material is legible and ordered correctly, and keep it separate from everyday connected devices.
  • Before important actions, disable unnecessary remote-control or sharing tools and keep the operating system and browser current.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
03

What to do when something looks wrong

Seed Phrase & Private Keys is easier to use when fake support and remote access are understood in the same operational context. Fake support commonly asks for seed phrases, private keys, verification codes, or remote-control access under the pretext of account verification, recovery, or troubleshooting. Remote-control software can expose the screen, inputs, and clicks to another party. Avoid letting an unknown person control a device during key, signature, or transfer operations. These situations are rarely improved by clicking faster; separate the object, permission, and expected result instead.

Do not treat a familiar interface as proof that a request is trustworthy. Around fake support and remote access, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • Official personnel will not ask for a seed phrase or private key; any such request is a high-risk signal.
  • If supposed support asks you to install a remote-access tool, stop the session and verify the source independently.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
04

Turn security into a repeatable habit

Seed Phrase & Private Keys is easier to use when seed phrase and private key are understood in the same operational context. A seed phrase can commonly restore a set of wallet accounts, making it more sensitive than an ordinary login password. If exposed, another party may be able to restore the wallet elsewhere. A private key directly controls the signing authority of an on-chain account. Anyone who obtains it may be able to produce valid signatures for that account. Understanding the boundary is more important than rushing to completion because on-chain actions can create difficult-to-reverse outcomes.

Do not treat a familiar interface as proof that a request is trustworthy. Around seed phrase and private key, identify the source of the request, the permission being granted, and whether an on-chain result may follow. imtoken will never ask for a seed phrase, private key, or verification code. Blockchain transactions also generally cannot be unilaterally reversed by a wallet, so review before confirmation matters more than recovery attempts afterward.

Practical checkpoint

  • Prefer offline backup, avoid screenshots and messaging apps, and never hand it to someone claiming to be support.
  • A private key is not a support credential, reward claim code, or website identity check; stop immediately if one is requested.
  • Before any transfer, signature, or approval, confirm that the network, address, and request details match the action you intended.
Security reminder

Keep seed phrases and private keys under your own control. Do not send them to anyone. Review the address, network, amount, signature text, and approval scope before confirming. Third-party DApps and smart contracts can introduce independent risk.