imtoken Knowledge Center
Phishing & Scams
Recognize fake sites, fake support, fraudulent airdrops, malicious signatures and social engineering around transfers.
On this page
Phishing Often Creates Urgency
When working with Phishing Often Creates Urgency, identify the network, target and permission involved before deciding what to approve or submit. Different networks can use similar address formats, and assets with similar names can exist on more than one chain. Icons and tickers are not enough for verification; network context, contract addresses and public explorer records provide stronger evidence. For concrete questions involving 钓鱼网站, use verifiable context instead of treating one successful past action as a permanent rule. Turning these checks into a routine reduces errors caused by the wrong network, the wrong target or misunderstood permissions.
Phishing Often Creates Urgency also makes more sense when it is evaluated within the full operation context. If a request is unclear, declining it and verifying first is usually safer than trying to repair the consequences later. This matters especially for signatures, approvals and cross-network actions because a confirmed blockchain transaction generally cannot be reversed by the wallet alone. For imtoken users, the goal is not complexity. The goal is a workflow that can be checked: confirm the network, confirm the target and permission, then confirm the on-chain result. If you cannot explain the purpose, target and expected result of a request, stop and verify it before continuing.
Fake Support Tries to Obtain Secrets
Fake Support Tries to Obtain Secrets may look like a single feature, but it usually combines address handling, network state, on-chain records and security boundaries. Security comes from a collection of habits rather than one setting: keep secret recovery material offline, keep devices under your control, verify domains and contracts, review old approvals and use a small test transaction when the context makes that useful. For concrete questions involving 假客服, use verifiable context instead of treating one successful past action as a permanent rule. If you cannot explain the purpose, target and expected result of a request, stop and verify it before continuing.
Fake Support Tries to Obtain Secrets also makes more sense when it is evaluated within the full operation context. Public troubleshooting data must remain separate from secret credentials. A transaction hash, public address and network name can often help explain a problem; a seed phrase, private key, recovery phrase or verification code should never be sent to another person or entered into an ordinary web page. For imtoken users, the goal is not complexity. The goal is a workflow that can be checked: confirm the network, confirm the target and permission, then confirm the on-chain result. A practical security test is whether you can answer four questions before submitting: who, on which network, doing what, and with what scope.
Airdrops and Approval Risk
Placing Airdrops and Approval Risk inside the full wallet workflow helps avoid decisions based only on balance displays, labels or third-party instructions. A wallet helps the user control keys and organize interactions, while the network is what records a valid transaction. Before an action, check the network, destination, amount or permission scope. After it, review status, confirmations and the transaction hash to verify what actually happened. For concrete questions involving 假空投, use verifiable context instead of treating one successful past action as a permanent rule. A practical security test is whether you can answer four questions before submitting: who, on which network, doing what, and with what scope.
Airdrops and Approval Risk also makes more sense when it is evaluated within the full operation context. Different networks can use similar address formats, and assets with similar names can exist on more than one chain. Icons and tickers are not enough for verification; network context, contract addresses and public explorer records provide stronger evidence. For imtoken users, the goal is not complexity. The goal is a workflow that can be checked: confirm the network, confirm the target and permission, then confirm the on-chain result. With that sequence in place, you can still make sound decisions even when the interface changes.
What to Do with a Suspicious Link
Decisions around What to Do with a Suspicious Link should be grounded in information that can be verified on-chain rather than unconfirmed screenshots or messages. If a request is unclear, declining it and verifying first is usually safer than trying to repair the consequences later. This matters especially for signatures, approvals and cross-network actions because a confirmed blockchain transaction generally cannot be reversed by the wallet alone. For concrete questions involving 恶意签名, use verifiable context instead of treating one successful past action as a permanent rule. With that sequence in place, you can still make sound decisions even when the interface changes.
What to Do with a Suspicious Link also makes more sense when it is evaluated within the full operation context. Security comes from a collection of habits rather than one setting: keep secret recovery material offline, keep devices under your control, verify domains and contracts, review old approvals and use a small test transaction when the context makes that useful. For imtoken users, the goal is not complexity. The goal is a workflow that can be checked: confirm the network, confirm the target and permission, then confirm the on-chain result. Turning these checks into a routine reduces errors caused by the wrong network, the wrong target or misunderstood permissions.
Security principles
Your seed phrase and private keys are controlled by you. imtoken staff will not ask for your seed phrase, private key or verification code. Review addresses, networks, amounts, signatures and approval scope before acting. Third-party DApps and smart contracts can carry risk, and confirmed on-chain transactions generally cannot be reversed by the wallet alone.
