imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

Phishing & Scams

Phishing and scams often use lookalike domains, fake support, airdrops, urgency and remote access to make users disclose keys or sign dangerous requests. Recognizing the pattern matters more than memorizing one example.

Use the page as a decision guide: identify the network, account and request before signing or moving assets.
On this page

Lookalike domains and search results

A fake domain may differ by one character and can appear prominently through ads or social links. Verify the full domain rather than trusting a familiar-looking design.

A repeatable order of checks is more reliable than memory. Review source, network, account, target and expected outcome each time so the same safety logic carries across wallets and DApps.

Fake support asks for control

Legitimate support does not need a seed phrase, private key or verification code. Stop any request that claims to “verify a wallet,” “sync a node” or “unlock assets” by asking for them.

When a task involves a third-party contract, bridge, validator or web service, separate that external risk from the wallet itself. A wallet can display and sign a request, but it cannot guarantee the safety of outside code or services.

Fake airdrops and malicious signatures

Unknown tokens, NFTs or reward links can lure users into connecting and signing permissions. A “free claim” is not a reason to skip contract, spender and signature review.

Put this concept back into the current network, account and request type before acting. Identify what the interface is asking for, then decide whether a signature, gas payment or ongoing permission is actually required.

Remote control and clipboard risks

Remote-control tools can expose or manipulate wallet actions, while malware can replace copied addresses. Recheck the full recipient before sending and do not operate a wallet while another person controls the device.

Do not rely on a button label or a familiar-looking page as the reason to continue. Compare the request with the on-chain target, network state and expected result, and stop when those pieces do not line up.

Practical checklist

  • Confirm that “Lookalike domains and search results” matches the task you intend to perform
  • Confirm that “Fake support asks for control” matches the task you intend to perform
  • Confirm that “Fake airdrops and malicious signatures” matches the task you intend to perform
  • Confirm that “Remote control and clipboard risks” matches the task you intend to perform

Risk reminder

Seed phrases and private keys remain under the user’s control. Legitimate support should not ask for a seed phrase, private key or verification code. Review address, network and amount before transferring; blockchain transactions generally cannot be unilaterally reversed by a wallet. Third-party DApps and smart contracts carry risk, so review spender and permission scope and consider revoking unused approvals.