imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Seed Phrase & Private Keys

Understand why seed phrases and private keys control assets, and the risks of screenshots, copying, cloud storage and poor offline backup.

On this pageControl of seed phrases and private keysCommon risk scenarios and warning signsChecks before transfer, signing and approvalDevice and network environmentPrinciples for responding to suspicious activity

Security comes from repeatable habits: keep keys private, verify domains and networks, understand signatures and approvals, manage device exposure and create enough time to review before acting.

Core principle

Keep recovery secrets private, verify requests independently, and assume that third-party DApps and smart contracts can carry risk.

Control of seed phrases and private keys

Security comes from repeatable habits: keep keys private, verify domains and networks, understand signatures and approvals, manage device exposure and create enough time to review before acting. In this section, control of seed phrases and private keys is treated as part of a complete workflow. Offline backup should balance recoverability with access control and should not rely on screenshots or chat messages. The practical question is what information is visible before an action, what can change on-chain, and what independent evidence can be checked afterward.

A reliable review separates interface labels from protocol facts. Confirm the active network, account, asset or contract involved, then compare the request with the outcome you actually expect. A seed phrase or private key can grant control over assets, so exposing either to another person can compromise the wallet directly. This approach is especially useful when different networks use similar address formats or when a DApp asks for permissions that remain active beyond one session.

Do not use urgency as a substitute for understanding. If a signature, approval, bridge, validator action or transfer cannot be explained in plain language, stop and verify the destination, network and permission scope before continuing. On-chain transactions are often not reversible by a wallet provider, so the strongest control is review before confirmation rather than recovery afterward.

Common risk scenarios and warning signs

Security comes from repeatable habits: keep keys private, verify domains and networks, understand signatures and approvals, manage device exposure and create enough time to review before acting. In this section, common risk scenarios and warning signs is treated as part of a complete workflow. A seed phrase or private key can grant control over assets, so exposing either to another person can compromise the wallet directly. The practical question is what information is visible before an action, what can change on-chain, and what independent evidence can be checked afterward.

A reliable review separates interface labels from protocol facts. Confirm the active network, account, asset or contract involved, then compare the request with the outcome you actually expect. Offline backup should balance recoverability with access control and should not rely on screenshots or chat messages. This approach is especially useful when different networks use similar address formats or when a DApp asks for permissions that remain active beyond one session.

Do not use urgency as a substitute for understanding. If a signature, approval, bridge, validator action or transfer cannot be explained in plain language, stop and verify the destination, network and permission scope before continuing. On-chain transactions are often not reversible by a wallet provider, so the strongest control is review before confirmation rather than recovery afterward.

Practical checks

  • Verify the active network and destination before confirming.
  • Treat every signature or approval as a separate decision.
  • Use transaction hashes and explorers to check on-chain state when relevant.
  • Keep seed phrases, private keys and verification codes private.

Checks before transfer, signing and approval

Security comes from repeatable habits: keep keys private, verify domains and networks, understand signatures and approvals, manage device exposure and create enough time to review before acting. In this section, checks before transfer, signing and approval is treated as part of a complete workflow. Offline backup should balance recoverability with access control and should not rely on screenshots or chat messages. The practical question is what information is visible before an action, what can change on-chain, and what independent evidence can be checked afterward.

A reliable review separates interface labels from protocol facts. Confirm the active network, account, asset or contract involved, then compare the request with the outcome you actually expect. A seed phrase or private key can grant control over assets, so exposing either to another person can compromise the wallet directly. This approach is especially useful when different networks use similar address formats or when a DApp asks for permissions that remain active beyond one session.

Do not use urgency as a substitute for understanding. If a signature, approval, bridge, validator action or transfer cannot be explained in plain language, stop and verify the destination, network and permission scope before continuing. On-chain transactions are often not reversible by a wallet provider, so the strongest control is review before confirmation rather than recovery afterward.

Security note

imtoken staff will never ask for your seed phrase or private key. Do not send seed phrases, private keys or verification codes to anyone.

Device and network environment

Security comes from repeatable habits: keep keys private, verify domains and networks, understand signatures and approvals, manage device exposure and create enough time to review before acting. In this section, device and network environment is treated as part of a complete workflow. A seed phrase or private key can grant control over assets, so exposing either to another person can compromise the wallet directly. The practical question is what information is visible before an action, what can change on-chain, and what independent evidence can be checked afterward.

A reliable review separates interface labels from protocol facts. Confirm the active network, account, asset or contract involved, then compare the request with the outcome you actually expect. Offline backup should balance recoverability with access control and should not rely on screenshots or chat messages. This approach is especially useful when different networks use similar address formats or when a DApp asks for permissions that remain active beyond one session.

Do not use urgency as a substitute for understanding. If a signature, approval, bridge, validator action or transfer cannot be explained in plain language, stop and verify the destination, network and permission scope before continuing. On-chain transactions are often not reversible by a wallet provider, so the strongest control is review before confirmation rather than recovery afterward.

Practical checks

  • Verify the active network and destination before confirming.
  • Treat every signature or approval as a separate decision.
  • Use transaction hashes and explorers to check on-chain state when relevant.
  • Keep seed phrases, private keys and verification codes private.

Principles for responding to suspicious activity

Security comes from repeatable habits: keep keys private, verify domains and networks, understand signatures and approvals, manage device exposure and create enough time to review before acting. In this section, principles for responding to suspicious activity is treated as part of a complete workflow. Offline backup should balance recoverability with access control and should not rely on screenshots or chat messages. The practical question is what information is visible before an action, what can change on-chain, and what independent evidence can be checked afterward.

A reliable review separates interface labels from protocol facts. Confirm the active network, account, asset or contract involved, then compare the request with the outcome you actually expect. A seed phrase or private key can grant control over assets, so exposing either to another person can compromise the wallet directly. This approach is especially useful when different networks use similar address formats or when a DApp asks for permissions that remain active beyond one session.

Do not use urgency as a substitute for understanding. If a signature, approval, bridge, validator action or transfer cannot be explained in plain language, stop and verify the destination, network and permission scope before continuing. On-chain transactions are often not reversible by a wallet provider, so the strongest control is review before confirmation rather than recovery afterward.

Continue with imtoken

Review the relevant network and security guidance before moving into asset or DApp operations.

Download imtoken