imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken · Security

Phishing & Scam Awareness

Build a clear working model of fake support, fake airdrops and phishing domains, with security checks integrated into every step.

Core security principles

Most mistakes around Phishing & Scam Awareness do not come from the interface itself.They come from misunderstanding networks, addresses, permissions or the finality of an on-chain action.A sound model of fake support should also include the later effects of clipboard risk.Network conditions and third-party services can change, so keep verifiable references such as transaction hashes when they are available.

Scams often use urgency, fake support, fake airdrops or look-alike domains to push users toward signing.Slowing down and verifying through an independent path is a strong defense.From a user perspective, the key information should be explainable and independently checkable rather than hidden behind default settings.imtoken places the concepts, the operating sequence and the security questions in one reading path so the decision can be reviewed before and after an action.

Common risk scenarios

Looking at fake support together with fake airdrops helps separate what is happening in the interface, what is controlled by the wallet account and what is recorded on the blockchain.Scams often use urgency, fake support, fake airdrops or look-alike domains to push users toward signing.Slowing down and verifying through an independent path is a strong defense.

If two sources appear to disagree, pause new actions first.Record the network, address or transaction reference you already have, then compare the result with an explorer or another reliable network view.Repeatedly submitting the same transaction can make a confusing situation harder to diagnose.

fake supportfake airdropsphishing domainsmalicious signaturesclipboard risk

How to recognize suspicious requests

In real use, fake support often appears alongside phishing domains.Verify the source first, then review the network and the exact request so similar names or simplified interface labels do not lead to the wrong conclusion.Scams often use urgency, fake support, fake airdrops or look-alike domains to push users toward signing.

Slowing down and verifying through an independent path is a strong defense.For unfamiliar workflows, a small test, a fresh domain check and a review of the contract or network details can be more valuable than speed.Secrets such as seed phrases and private keys should never be provided to a third party as a form of identity verification.

Practical check

  • Confirm the address or contract target before approving.
  • Confirm the network and the asset used for network fees.
  • Read the exact signature, approval or transaction request.
  • Keep transaction references for later verification when available.

What to do when something looks wrong

When an action involves fake airdrops, malicious signatures or clipboard risk, the button label is not enough.Review the target, scope, network state and the likely result after the action is approved.Scams often use urgency, fake support, fake airdrops or look-alike domains to push users toward signing.

Slowing down and verifying through an independent path is a strong defense.After the action, verify that the resulting state matches what you intended and check whether an unnecessary connection or approval remains.Over time, review device security, backup practices and active permissions instead of treating security as a one-time setup task.

Long-term security habits

The practical value of understanding phishing domains is a repeatable review process.A useful sequence is source check, network check, request review and outcome verification.Scams often use urgency, fake support, fake airdrops or look-alike domains to push users toward signing.

Slowing down and verifying through an independent path is a strong defense.Self-custody gives users direct control, but it also means responsibility does not automatically move to the wallet interface.Understanding the boundaries of the workflow helps maintain the same decision standard when moving between different networks, applications and contract interactions.