imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · SECURITY

Phishing & Scam Awareness

Phishing & Scam Awareness: practical guidance for fake support, fake airdrops, lookalike sites, malicious signature prompts, with decision points, checks and risk notes.

Phishing & Scam Awareness topic illustration

Core Security Principles

Lookalike sites can arrive through ads, direct messages or nearly identical domains. Verify the full domain and use a trusted entry point before connecting a wallet. The practical way to understand Phishing & Scam Awareness is to place it inside a real user journey rather than memorize isolated terms. 识别假客服、假空投、仿冒站点与恶意签名诱导 should be checked before an action, during confirmation and again after completion. Verify the entry point and network first, read addresses, permissions, fees and request details at confirmation, then use on-chain records to validate the outcome.

Many mistakes around Phishing & Scam Awareness begin with information that looks familiar: similar network names, address formats, token symbols or interface layouts. Prefer details that can be independently checked, such as the full domain, network name, contract address, transaction hash and a matching block-explorer record, instead of relying on icons, nicknames or screenshots. For Phishing & Scam Awareness, break the task into small points that can be verified rather than continuing while the network, address, permission or transaction state is still unclear.

Pre-action check

Confirm that the page and network match the task, then review public addresses, assets, fees or permission details. A familiar interface is not a reason to skip the request details of a third-party DApp or smart contract.

Common Risk Scenarios

Fake support, fake airdrops and urgent account warnings often create pressure to sign immediately or reveal recovery information. Many mistakes around Phishing & Scam Awareness begin with information that looks familiar: similar network names, address formats, token symbols or interface layouts. Prefer details that can be independently checked, such as the full domain, network name, contract address, transaction hash and a matching block-explorer record, instead of relying on icons, nicknames or screenshots.

imtoken treats user review as the final decision point for Phishing & Scam Awareness. This site never asks for seed phrases, private keys or verification codes, and it does not promise that confirmed on-chain transactions can be reversed by the wallet. DApps, smart contracts, networks and third-party services each introduce their own risk boundaries. For Phishing & Scam Awareness, break the task into small points that can be verified rather than continuing while the network, address, permission or transaction state is still unclear.

Confirmation check

Confirm that the page and network match the task, then review public addresses, assets, fees or permission details. A familiar interface is not a reason to skip the request details of a third-party DApp or smart contract.

How to Identify Suspicious Requests

When a request is unclear, stop the interaction, reopen a known entry point independently and refuse to share seed phrases, private keys or verification codes. imtoken treats user review as the final decision point for Phishing & Scam Awareness. This site never asks for seed phrases, private keys or verification codes, and it does not promise that confirmed on-chain transactions can be reversed by the wallet. DApps, smart contracts, networks and third-party services each introduce their own risk boundaries.

If the result differs from what you expected, preserve non-secret details such as the transaction hash, network and public address, then begin troubleshooting from on-chain state. Never send recovery information to someone claiming to provide support, and do not sign an unfamiliar request simply because it is presented as a fix. For Phishing & Scam Awareness, break the task into small points that can be verified rather than continuing while the network, address, permission or transaction state is still unclear.

Post-action check

Confirm that the page and network match the task, then review public addresses, assets, fees or permission details. A familiar interface is not a reason to skip the request details of a third-party DApp or smart contract.

What to Do When Something Looks Wrong

Lookalike sites can arrive through ads, direct messages or nearly identical domains. Verify the full domain and use a trusted entry point before connecting a wallet. If the result differs from what you expected, preserve non-secret details such as the transaction hash, network and public address, then begin troubleshooting from on-chain state. Never send recovery information to someone claiming to provide support, and do not sign an unfamiliar request simply because it is presented as a fix.

The practical way to understand Phishing & Scam Awareness is to place it inside a real user journey rather than memorize isolated terms. 识别假客服、假空投、仿冒站点与恶意签名诱导 should be checked before an action, during confirmation and again after completion. Verify the entry point and network first, read addresses, permissions, fees and request details at confirmation, then use on-chain records to validate the outcome. For Phishing & Scam Awareness, break the task into small points that can be verified rather than continuing while the network, address, permission or transaction state is still unclear.

Pre-action check

Confirm that the page and network match the task, then review public addresses, assets, fees or permission details. A familiar interface is not a reason to skip the request details of a third-party DApp or smart contract.

Everyday Security Checklist

Fake support, fake airdrops and urgent account warnings often create pressure to sign immediately or reveal recovery information. The practical way to understand Phishing & Scam Awareness is to place it inside a real user journey rather than memorize isolated terms. 识别假客服、假空投、仿冒站点与恶意签名诱导 should be checked before an action, during confirmation and again after completion. Verify the entry point and network first, read addresses, permissions, fees and request details at confirmation, then use on-chain records to validate the outcome.

Many mistakes around Phishing & Scam Awareness begin with information that looks familiar: similar network names, address formats, token symbols or interface layouts. Prefer details that can be independently checked, such as the full domain, network name, contract address, transaction hash and a matching block-explorer record, instead of relying on icons, nicknames or screenshots. For Phishing & Scam Awareness, break the task into small points that can be verified rather than continuing while the network, address, permission or transaction state is still unclear.

Confirmation check

Confirm that the page and network match the task, then review public addresses, assets, fees or permission details. A familiar interface is not a reason to skip the request details of a third-party DApp or smart contract.

Important note

You are responsible for keeping seed phrases and private keys private. imtoken personnel will never ask for them. Verify address, network and amount before sending; confirmed on-chain transactions generally cannot be reversed by the wallet.