imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Security

Transaction Checks

Use a three-stage review before transfer, during signing and after broadcast to reduce address, network and amount mistakes.

Security principle: Keep your seed phrase and private keys under your own control. imtoken staff will not ask for them.
Table of contents
Core security principlesCommon risk scenariosHow to recognize an abnormal requestWhat to do when something looks wrongA long-term security checklist

Core security principles

When working with Transaction Checks, the useful starting point is not memorizing where a button sits. It is understanding how address verification, network verification, and amount verification relate to one another. A wallet presents account information and on-chain state together, while the actual transfer, contract call, or approval is recorded according to the rules of the selected network. Before confirming anything, identify what you are acting on, which network is involved, and what result you expect to see.

In the context of Core security principles, treat address verification as the object you are working with, network verification as the environment, and amount verification as the action. Use gas review, transaction hash, and confirmation status to verify cost, scope, and outcome. If one of these elements conflicts with what you intended, a polished interface is not enough evidence to continue. For a new network, contract, or DApp, a small and easily verifiable first action can help you understand the flow before taking a more complex step.

Common risk scenarios

Review network verification and gas review as part of the same decision rather than as separate details. A seemingly simple action can include an address, network, fee, permission scope, or confirmation state. Do not rely only on an asset symbol or a friendly interface label. Compare the full address, the network, relevant contract information, and the expected outcome. If those details do not line up, stop and return to the source of the request before proceeding.

You do not need to master every protocol detail at once, but you should know which details control the result. address verification tells you what you are looking at, network verification provides context, and amount verification describes the requested action. gas review and transaction hash may determine cost or permission, while confirmation status helps verify what actually happened. That distinction turns 'what I clicked' into a clearer understanding of 'what the network recorded.'

Key points to compare

  • address verification
  • network verification
  • amount verification
  • gas review

How to recognize an abnormal request

A practical sequence is: verify the source, inspect the parameters, confirm deliberately, then review the on-chain result. Requests involving amount verification should match an action you initiated. Requests involving transaction hash deserve a careful look at scope, counterparty, and duration. After completion, use transaction history or a blockchain explorer to verify the result. This turns a high-impact action into a series of explicit checkpoints instead of a single reflexive click.

In the context of How to recognize an abnormal request, treat address verification as the object you are working with, network verification as the environment, and amount verification as the action. Use gas review, transaction hash, and confirmation status to verify cost, scope, and outcome. If one of these elements conflicts with what you intended, a polished interface is not enough evidence to continue. For a new network, contract, or DApp, a small and easily verifiable first action can help you understand the flow before taking a more complex step.

What to do when something looks wrong

gas review and confirmation status are often important when deciding whether an operation completed as expected. A delayed interface update does not necessarily mean assets are missing, and a failed transaction may still have consumed network fees. Look for the transaction hash, confirmation count, contract execution status, or current network conditions. When a third-party DApp, bridge, Layer 2 tool, or smart contract is involved, include that third party's behavior and contract risk in your assessment.

You do not need to master every protocol detail at once, but you should know which details control the result. address verification tells you what you are looking at, network verification provides context, and amount verification describes the requested action. gas review and transaction hash may determine cost or permission, while confirmation status helps verify what actually happened. That distinction turns 'what I clicked' into a clearer understanding of 'what the network recorded.'

Risk checks
  • Do not share a seed phrase, private key or verification code
  • Check the address, network and amount
  • Review every signing or approval request separately
  • Consider revoking approvals that are no longer needed

A long-term security checklist

Security should be part of the entire workflow, not an isolated setup step. Keep seed phrases and private keys under your own control and preferably backed up offline. imtoken staff will not ask for a seed phrase, private key, or verification code. Check the destination address, network, and amount before sending. Read signing and approval requests before accepting them, and review permissions you no longer need. On-chain transactions generally cannot be reversed unilaterally by a wallet, so prevention matters more than recovery promises.

In the context of A long-term security checklist, treat address verification as the object you are working with, network verification as the environment, and amount verification as the action. Use gas review, transaction hash, and confirmation status to verify cost, scope, and outcome. If one of these elements conflicts with what you intended, a polished interface is not enough evidence to continue. For a new network, contract, or DApp, a small and easily verifiable first action can help you understand the flow before taking a more complex step.

Continue with imtoken

Use the download entry only when you are ready, and review network and security information before acting.

Download imtoken