imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

Phishing & Scams

Phishing pages, fake support, fake airdrops and remote-access tricks often create urgency. Reject any request for a seed phrase or private key.

Scams often create urgency before asking for action

Fake support, airdrops, recovery services, and account warnings commonly try to make users skip verification. Pause when a message insists that action must happen immediately.

Judge the request by what it asks you to do, not by the profile picture or tone of the sender.

Look-alike domains are a common trap

Phishing sites can change one character, add a prefix, or use visually similar letters. Read the complete browser address rather than relying on a search-result title.

Save verified entry points for services you use regularly.

Public transaction knowledge does not prove identity

Addresses and transaction hashes are public, so a scammer can cite accurate transaction details and still be an impostor.

A support agent asking for a private key, seed phrase, verification code, or remote control should be treated as unsafe.

Unsolicited tokens and NFTs can be bait

Anyone can send assets to a public address. Their presence in your wallet does not make attached links trustworthy.

There is no need to connect to an unknown site simply to “unlock” an unsolicited asset.

Preserve public evidence after a suspicious interaction

Stop new signatures, record the domain, transaction hashes, spender addresses, and timeline, then review approvals and device state.

Do not pay a second unknown service or share secrets in an attempt to recover losses.

Public data is not proof of support identity

Anyone can inspect an address and its history.

How to verify a suspicious message

Do not keep following links inside the suspicious conversation. Open a known official entry point independently and compare the requested action with normal product behavior.

Evaluate requested actions, not persuasive language

Use public transaction hashes to verify chain status. Most transaction questions can be investigated without revealing private key material.

If remote-control software was installed, end the session and inspect the device before continuing wallet activity.

  • Pause when a message creates artificial urgency
  • Verify domains through an independent entry point
  • Never share seed phrases, private keys, or verification codes
  • Review approvals, device state, and transactions after suspicious activity