imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

imtoken App

Understand how accounts, networks, assets and transaction history fit together in a mobile wallet, with clear checks at each step.

The mobile app is a key-use environment on your device

imtoken App organizes accounts, networks, asset views, transaction history, and DApp requests on a mobile device. The assets still exist as blockchain state; the app uses locally available keys to sign requests and reads data from the selected network.

Moving to a new phone is therefore different from moving assets. Recovery material preserves control of the account history; the device is the environment in which that control is exercised.

Unlocking the app is not the same as confirming the account

A phone can contain several accounts or wallets. After opening the app, verify the active address and network, especially when returning from a browser, a notification, or a deep link.

Biometrics and a device PIN protect local access. They do not replace the seed-phrase backup and they cannot prevent a user from approving the wrong transaction.

Network changes alter balances, gas, and contract context

Switching networks can change the visible assets, native fee currency, transaction history, and available contracts. Similar EVM address formats make it easy to overlook that context change.

If an asset appears to be missing, check the active network and token contract before assuming the account needs to be restored or re-imported.

Mobile transfers need clipboard and QR-code checks

Copy-and-paste and QR scanning reduce typing, but the clipboard can be manipulated and a QR code can still point to the wrong network or address. Review the destination after pasting or scanning.

For a large or unfamiliar transfer, a small test followed by an on-chain check can reduce the impact of a routing mistake.

DApp requests remain separate decisions inside the app

A DApp session can lead to connection requests, message signatures, token approvals, and transactions. Each carries a different effect and should be reviewed on its own.

Check the domain, account, network, contract, spender, amount, and visible request data. If the request does not match the action you initiated, cancel it and re-check the source.

The phone itself is part of the security boundary

Keep the operating system and app current, use a strong screen lock, and be cautious with accessibility permissions, screen sharing, remote control, and software from unknown sources.

Recovery material should not live in the photo library, chat history, or an ordinary cloud note. A locked phone does not make synced screenshots private from every other account or app.

Mobile security

Biometrics and device passwords protect local access; they do not recover a seed phrase and they do not replace transaction review.

Turn fast mobile actions into deliberate checks

Mobile interfaces are designed for speed, so create an intentional review pause. Confirm the account and network after opening the app; check the destination and gas before sending; and treat connection, signing, approval, and transaction prompts as separate actions.

Use a short pause before every irreversible action

If you see unexpected network switching, unknown signatures, repeated prompts, or requests for remote assistance, exit the flow instead of clicking through. Re-open the app on a trusted network and use public chain data to inspect recent transactions and approvals.

  • Confirm the active account and network after unlocking.
  • Review pasted or scanned destinations before sending.
  • Read every signature, approval, and transaction request independently.
  • Do not screenshot or send seed phrases to a supposed support agent.