Core security principle
Sensitive wallet credentials remain under user control. Never send them to anyone.
Start with the core concepts
Phishing & Scams is best understood by seeing how look-alike domains, fake support, fake airdrops, malicious signatures, clipboard attacks and remote control relate to one another rather than memorizing a button or screen. A wallet helps organize keys, addresses, networks and requests, but final state is determined by the selected blockchain. Before acting, identify who controls the address, which network is selected, what asset or contract is involved, and where the result can be independently verified.
Use a deliberate review sequence
For phishing & scams, use a fixed sequence: source, network, address, amount or permission, then result. Confirm the origin and domain, verify the intended network, and review the destination, asset, amount and gas for transfers. For DApps and contracts, inspect the exact signature, spender, allowance and contract address. After submission, keep the transaction hash and use the appropriate block explorer to review inclusion and confirmations.
Common mistakes and risk boundaries
Risk around phishing & scams often comes from the wrong network, an altered address, excessive approval, an unexpected signature, or treating an interface message as final on-chain truth. Confirmed blockchain transactions are generally not reversible by a wallet alone, and third-party DApps, contracts, bridges or services can introduce technical and operational risk. imtoken will never ask for a seed phrase, private key or verification code.
Build a repeatable routine
A more reliable approach is to make phishing & scams part of a long-term routine. Keep seed phrases and private keys under your own control and preferably backed up offline. Recheck addresses, networks and amounts before sending, read requests before signing, verify approval scope before granting it, retain transaction hashes, and periodically remove connections or permissions that are no longer needed.
Checklist
- Verify the source and domain.
- Confirm network and address.
- Review amount, gas or permission scope.
- Keep the transaction hash for verification.
Never share your seed phrase, private key or verification code. Review every transfer, signature and approval independently.
