imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

Create & Backup

Creating a wallet is only the start. Long-term access depends on backups, offline storage, recovery checks and private-key discipline.

Distinguish a new wallet from restoration before you begin

Creating a new wallet generates new recovery material and a new key relationship. Restoring or importing uses existing material to regain control of an existing account. Make sure you know which goal you are pursuing before recording or entering any secret.

Restoration does not move assets from the blockchain to the device. It simply makes the current device able to sign for the account again.

Seed phrases and private keys represent different scopes of control

A seed phrase can often derive multiple accounts and keys, while a private key directly controls a particular account. Both are high-value secrets and should be treated as credentials that cannot be safely shared.

imtoken support will not ask for a seed phrase, private key, or verification code. “Wallet verification” or “sync” pages that request recovery material are a major warning sign.

A useful backup is offline, accurate, and readable

The goal is to reduce exposure to connected services while preserving the ability to recover after device loss or failure. Screenshots, chat history, and ordinary cloud notes can be copied by accounts, apps, or synchronization services.

Record every word accurately and preserve the order. Do not upload the phrase to an online tool merely to test whether it is correct.

Verification should not disclose the recovery material

Use trusted local confirmation steps or a carefully controlled recovery rehearsal if you need to confirm that the backup can be read. Avoid entering the complete phrase into an unfamiliar website, support form, or remote-assistance session.

If you cannot establish that the software and environment are trustworthy, stop before exposing the secret.

Device migration requires attention to both devices

After restoring on a new device, the old device does not automatically lose its wallet data or active sessions. Review local access, browser sessions, and app locks on both devices.

If a lost device may be unlocked by someone else, assess whether the underlying keys could be exposed and whether moving assets to newly generated keys is appropriate.

Treat suspected exposure as real exposure

If a seed phrase or private key was sent to another person, entered into a suspicious page, included in a public screenshot, or visible during remote control, changing the app password is not enough.

Stop using the affected key material for new activity, inspect recent transactions and approvals, and plan any migration from a trusted device.

Backup baseline

Never send a seed phrase, private key, or recovery phrase to support, an airdrop page, or a “security check.”

Review the backup before and after storage

More copies are not automatically safer. A backup should be controlled by you, readable when needed, and difficult for an online account or unrelated person to copy. Additional physical copies can improve resilience but also create more places where the secret can be discovered or lost.

Balance backup resilience with exposure risk

Recovery material is not an ordinary account password with a reliable reset process. Plan how you will locate and read it in an emergency without making the actual words available to people who do not need them.

  • Know whether you are creating or restoring before entering any secret.
  • Verify word order and spelling without using screenshots or online validators.
  • Enter recovery material only into trusted local wallet software.
  • If exposure is suspected, stop using the affected keys and assess migration.