imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

Create & Backup

When creating or importing a wallet, understand the relationship between seed phrases, private keys and recovery. Build a backup method that does not depend on unknown web pages, chats or cloud screenshots.

Use the page as a decision guide: identify the network, account and request before signing or moving assets.
On this page

Understand keys before creating

A new wallet creates key material that controls accounts. Prepare a private environment first, and recognize that entering a seed phrase into an unfamiliar website is not a safe backup process.

A common mistake is to treat a normal-looking interface as proof that the underlying blockchain action is correct. Public addresses, transaction hashes, contract addresses and network parameters provide independent ways to verify what is happening.

Record the seed phrase offline

A backup should be accurate, complete and private. Avoid screenshots, public printing services, chat forwarding and automatic cloud sync. Store the record where access is appropriately controlled.

A repeatable order of checks is more reliable than memory. Review source, network, account, target and expected outcome each time so the same safety logic carries across wallets and DApps.

Reduce exposure when importing

When restoring an existing wallet, enter sensitive information only in a trusted wallet environment. Avoid remote control, screen sharing and public devices, then confirm the device remains secure afterward.

When a task involves a third-party contract, bridge, validator or web service, separate that external risk from the wallet itself. A wallet can display and sign a request, but it cannot guarantee the safety of outside code or services.

Verify without disclosing

Verify order, spelling and completeness without sending the phrase to anyone claiming to validate it. Recovery capability remains under the user’s own control.

Put this concept back into the current network, account and request type before acting. Identify what the interface is asking for, then decide whether a signature, gas payment or ongoing permission is actually required.

Practical checklist

  • Confirm that “Understand keys before creating” matches the task you intend to perform
  • Confirm that “Record the seed phrase offline” matches the task you intend to perform
  • Confirm that “Reduce exposure when importing” matches the task you intend to perform
  • Confirm that “Verify without disclosing” matches the task you intend to perform

Risk reminder

Seed phrases and private keys remain under the user’s control. Legitimate support should not ask for a seed phrase, private key or verification code. Review address, network and amount before transferring; blockchain transactions generally cannot be unilaterally reversed by a wallet. Third-party DApps and smart contracts carry risk, so review spender and permission scope and consider revoking unused approvals.