imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken Knowledge

Approval Security

A practical guide to approval security with clear concepts, user checks and risk boundaries before wallet actions are confirmed.

On this page
  1. Approval targets
  2. Permission scope
  3. Malicious signing requests
  4. Periodic reviews

Approval targets

Approval targets is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. imtoken does not ask users to enter seed phrases, private keys or recovery phrases into content pages. On-chain transactions generally cannot be reversed by a wallet provider, so confirmation should always follow the user’s own review.

Approval targets is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. imtoken does not ask users to enter seed phrases, private keys or recovery phrases into content pages. On-chain transactions generally cannot be reversed by a wallet provider, so confirmation should always follow the user’s own review.

Practical checks

  • Confirm the current account and network
  • Never share a seed phrase, private key or verification code
  • Read the full transfer, signature or approval request before confirming

Permission scope

Permission scope is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. When something is unclear, stop and re-check through a trusted entry point rather than following an unfamiliar link, screenshot instruction or remote-control request. A small test transaction can be useful before a high-value transfer.

Permission scope is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. When something is unclear, stop and re-check through a trusted entry point rather than following an unfamiliar link, screenshot instruction or remote-control request. A small test transaction can be useful before a high-value transfer.

Practical checks

  • Keep the transaction hash for later checks
  • Use the relevant block explorer to verify on-chain status
  • Stop and re-check when the source or request is unclear

Malicious signing requests

Malicious signing requests is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. imtoken does not ask users to enter seed phrases, private keys or recovery phrases into content pages. On-chain transactions generally cannot be reversed by a wallet provider, so confirmation should always follow the user’s own review.

Malicious signing requests is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. imtoken does not ask users to enter seed phrases, private keys or recovery phrases into content pages. On-chain transactions generally cannot be reversed by a wallet provider, so confirmation should always follow the user’s own review.

Practical checks

  • Keep the transaction hash for later checks
  • Use the relevant block explorer to verify on-chain status
  • Stop and re-check when the source or request is unclear

Periodic reviews

Periodic reviews is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. When something is unclear, stop and re-check through a trusted entry point rather than following an unfamiliar link, screenshot instruction or remote-control request. A small test transaction can be useful before a high-value transfer.

Periodic reviews is an essential part of understanding Approval Security. Treat every wallet request as a decision with consequences. Check the source, understand the requested permission, and confirm that the action is actually necessary. A site, support account or promotion that asks for a seed phrase, private key or verification code should be treated as a serious warning sign. When something is unclear, stop and re-check through a trusted entry point rather than following an unfamiliar link, screenshot instruction or remote-control request. A small test transaction can be useful before a high-value transfer.

Practical checks

  • Keep the transaction hash for later checks
  • Use the relevant block explorer to verify on-chain status
  • Stop and re-check when the source or request is unclear