imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Security

Phishing & Scam Awareness

This guide connects the practical decisions behind spoofed websites, fake support, and fake airdrops. It focuses on verifiable on-chain information, clear user actions, and security habits that remain useful even when interfaces change.

Security principle

Reject any page, person or remote-access request that asks for a seed phrase, private key or verification code.

Core principle

Reduce exposure and verify every sensitive request

Security depends on repeatable checks: protect recovery credentials, verify origins, understand permissions and confirm the on-chain consequence.

On this page
  1. Build a repeatable security routine
  2. Recognize risks around spoofed websites
  3. Review fake support and fake airdrops before acting
  4. What to do when something looks wrong
  5. A practical security checklist
  6. The boundaries that should not change

Build a repeatable security routine

Phishing & Scam Awareness is best approached as a sequence of checks rather than a promise that any wallet can remove all risk. Identify who is asking you to act, what permission is being requested, which network or contract is involved, and what will change if you approve; in Phishing & Scam Awareness, read this specifically alongside “Build a repeatable security routine” and spoofed websites. imtoken staff will not ask for a seed phrase, private key, or verification code; in Phishing & Scam Awareness, read this specifically alongside “Build a repeatable security routine” and spoofed websites. Those credentials remain under the user’s control and should never be uploaded, pasted into chat, or shown through remote-access software; in Phishing & Scam Awareness, read this specifically alongside “Build a repeatable security routine” and spoofed websites. If “Build a repeatable security routine” is unclear, stop before approving and return to the basics of spoofed websites and fake support, then verify the result with a transaction hash, contract address or block record where applicable.

Recognize risks around spoofed websites

Problems involving spoofed websites often begin with a misleading page, an urgent message, or a request that does not match the task you intended to perform. Re-check the domain, the connected account, and the reason for the request; in Phishing & Scam Awareness, read this specifically alongside “Recognize risks around spoofed websites” and fake support. Promises of rewards, account “verification,” urgent upgrades, or support assistance should never be used as a reason to skip basic checks; in Phishing & Scam Awareness, read this specifically alongside “Recognize risks around spoofed websites” and fake support. A durable routine for Phishing & Scam Awareness is to make fake support a first-pass check, use fake airdrops as a second check, and rely on verifiable information related to malicious links rather than interface assumptions.

Review fake support and fake airdrops before acting

When reviewing fake support and fake airdrops, separate the object, the scope, and the consequence. The object may be an address, contract, device, or account; the scope may be a single transaction or a continuing approval; the consequence is what can happen after confirmation; in Phishing & Scam Awareness, read this specifically alongside “Review fake support and fake airdrops before acting” and fake airdrops. If the interface does not give enough context, stop and verify the address, transaction, or contract through the correct blockchain explorer; in Phishing & Scam Awareness, read this specifically alongside “Review fake support and fake airdrops before acting” and fake airdrops. This part of Phishing & Scam Awareness should be read together with the surrounding workflow: fake airdrops affects how you interpret malicious links, while clipboard risk helps confirm the state after the action.

Stop and verify
  • A request asks for recovery credentials or a verification code.
  • The domain, account or permission does not match your task.
  • Urgency or rewards are used to pressure you into approving.

What to do when something looks wrong

If activity appears suspicious, avoid repeated clicks in the same session; in Phishing & Scam Awareness, read this specifically alongside “What to do when something looks wrong” and malicious links. Disconnect unnecessary DApps, review recent transactions and token approvals, and move to a trusted device if the current environment may be compromised; in Phishing & Scam Awareness, read this specifically alongside “What to do when something looks wrong” and malicious links. Blockchain transactions are generally not something a wallet provider can unilaterally reverse, so the useful goal is to limit further exposure rather than trust anyone promising a guaranteed recovery; in Phishing & Scam Awareness, read this specifically alongside “What to do when something looks wrong” and malicious links. For Phishing & Scam Awareness, connect malicious links with clipboard risk and remote access; the important part is the relationship between those concepts and the on-chain evidence you can verify afterward.

A practical security checklist

A consistent routine can cover malicious links, clipboard risk, and most other Web3 interactions: use a trusted device, confirm the site, verify the network and destination, read each signature or approval, check the amount and fee, then review the transaction hash afterwards. Remove permissions that are no longer needed and keep recovery credentials offline; in Phishing & Scam Awareness, read this specifically alongside “A practical security checklist” and clipboard risk. When working through “A practical security checklist,” check the source, network, request details and resulting state in that order, with extra attention to clipboard risk and remote access.

The boundaries that should not change

The durable rules are simple: never share a seed phrase or private key, treat third-party DApps and smart contracts as independent risk sources, verify the address/network/amount before a transfer, and review approval scope before granting access; in Phishing & Scam Awareness, read this specifically alongside “The boundaries that should not change” and remote access. imtoken provides wallet tools and educational material; it does not guarantee the security of third-party contracts, network availability, or asset prices; in Phishing & Scam Awareness, read this specifically alongside “The boundaries that should not change” and remote access. Do not treat an interface success message as the final answer for Phishing & Scam Awareness. Use remote access, spoofed websites and fake support to confirm that the expected change occurred on the intended network.

Security and risk reminder

Seed phrases and private keys are controlled by the user. imtoken will never ask for them. Blockchain transactions are generally irreversible by a wallet provider, and third-party DApps, smart contracts, network conditions and digital-asset prices can introduce additional risk.