imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

imtoken Web

imtoken Web focuses on browser-based wallet connections, account requests and approval review. The goal is not simply to connect, but to understand what each step authorizes.

Use the page as a decision guide: identify the network, account and request before signing or moving assets.
01What a browser connection means
02Verify the domain first
03Separate signatures from transactions
04Disconnecting versus revoking
Browser connections should be reviewed one request at a time.
01

What a browser connection means

A website connection usually exposes only the account information you allow. Material permission changes happen later through signatures, transactions or token approvals.

02

Verify the domain first

Browser environments are exposed to lookalike pages and redirects. Verify the domain, page source and intended task before connecting rather than trusting a search result or prominent placement.

03

Separate signatures from transactions

A message signature may not move assets directly, but it can authenticate, authorize or prove account control. A transaction signature submits a state change to the network. Both deserve review.

Disconnecting versus revoking

Closing a page or disconnecting ends the session but may not change an existing on-chain token approval. Review unused approvals separately and revoke them when appropriate.

Put this concept back into the current network, account and request type before acting. Identify what the interface is asking for, then decide whether a signature, gas payment or ongoing permission is actually required.

Use least privilege for browser sessions

A browser may contain several tabs, redirects, and pages with visually similar domains, so domain checking matters both before and after connecting. When a wallet asks which account to expose, share only what is needed for the task. Treat every later message signature, transaction signature, or token approval as a new decision rather than as an automatic continuation of the connection.

If the requested action, contract target, or allowance cannot be matched to your purpose, cancel it instead of approving first and investigating later. Closing a page ends the browser session but does not automatically remove an approval already recorded on-chain. When a DApp is no longer needed, review its approvals separately and revoke permissions that no longer serve a purpose.

Practical checklist

  • Confirm that “What a browser connection means” matches the task you intend to perform
  • Confirm that “Verify the domain first” matches the task you intend to perform
  • Confirm that “Separate signatures from transactions” matches the task you intend to perform
  • Confirm that “Disconnecting versus revoking” matches the task you intend to perform

Risk reminder

Seed phrases and private keys remain under the user’s control. Legitimate support should not ask for a seed phrase, private key or verification code. Review address, network and amount before transferring; blockchain transactions generally cannot be unilaterally reversed by a wallet. Third-party DApps and smart contracts carry risk, so review spender and permission scope and consider revoking unused approvals.

Continue with imtoken

Use the unified download entry and review every network and permission request.

Download imtoken