imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Security Center

Device Security

A practical imtoken guide to device security, including core concepts, verification steps and risk-aware usage.

imtoken staff will never ask for your seed phrase, private key or verification code.

Offline wallet security
01

Core concepts

When using imtoken for Device Security, prioritize information that can be independently verified, such as addresses, network names, contract addresses, transaction hashes and block-explorer records. Visual design, urgency messages or claims from an unknown support account are not substitutes for verifiable on-chain details.

For public Wi-Fi, first define its role in the current task, then check whether shared computers and remote control are consistent. When clipboard risks is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For system updates, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: public Wi-Fi
  • Cross-check: shared computers and remote control
  • Review carefully: clipboard risks
  • Verify afterward: system updates
02

Checks before you act

From a risk perspective, clipboard risks and system updates deserve an independent review. Once a transaction is confirmed on-chain, a wallet normally cannot reverse it unilaterally. DApps and smart contracts can also introduce permission and contract risks, so every signature, approval and transfer should be understood before it is accepted.

For shared computers, first define its role in the current task, then check whether remote control and clipboard risks are consistent. When system updates is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For public Wi-Fi, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: shared computers
  • Cross-check: remote control and clipboard risks
  • Review carefully: system updates
  • Verify afterward: public Wi-Fi
03

How to evaluate a live request

After a Device Security task is completed, review public Wi-Fi and shared computers to make sure the outcome matches the intent. Long-lived approvals and persistent connections should be revisited periodically. Good wallet hygiene is a repeated process of checking critical details and retaining traceable on-chain information, not a one-time setting.

For remote control, first define its role in the current task, then check whether clipboard risks and system updates are consistent. When public Wi-Fi is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For shared computers, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: remote control
  • Cross-check: clipboard risks and system updates
  • Review carefully: public Wi-Fi
  • Verify afterward: shared computers
04

Risks and boundaries

To understand Device Security, treat clipboard risks and system updates as parts of the same on-chain workflow. The interface is only the entry point; the selected network, current chain state and permission scope determine what actually happens. Confirm the destination, source and network before continuing so the meaning of the request stays clear.

For clipboard risks, first define its role in the current task, then check whether system updates and public Wi-Fi are consistent. When shared computers is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For remote control, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: clipboard risks
  • Cross-check: system updates and public Wi-Fi
  • Review carefully: shared computers
  • Verify afterward: remote control
05

How to verify the outcome

system updates rarely appears in isolation. It often intersects with public Wi-Fi and shared computers. A useful pattern is to separate each action into four checks: identify the object, verify the network, review permissions, and confirm the result. If one of those checks cannot be completed, stop and verify rather than relying on an unfamiliar site or remote instructions.

For system updates, first define its role in the current task, then check whether public Wi-Fi and shared computers are consistent. When remote control is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For clipboard risks, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: system updates
  • Cross-check: public Wi-Fi and shared computers
  • Review carefully: remote control
  • Verify afterward: clipboard risks

Security checklist

  • Never share your seed phrase, private key or verification code.
  • Verify the address, network and amount before sending.
  • Review each DApp signature and token approval independently.
  • Use transaction hashes and block explorers to verify on-chain status.
  • Revoke approvals and disconnect sessions that are no longer needed.