imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Security Center

Device Security: Phones, Computers, Networks and Remote Control

Wallet security depends on more than seed-phrase storage. System updates, screen locks, app sources, public networks and remote-control access all affect exposure.

On this page
Maintain basic device protectionBe cautious with public Wi-Fi and shared computersClipboard and screen content can leak tooTreat remote-control requests as a major warning

Maintain basic device protection

Use screen locks and reasonable access control, keep the operating system and common software updated, and minimize apps, extensions or profiles from unknown sources. Device security includes updates, screen locks, software sources, clipboard behavior, remote-control access and the risks of public computers or networks. For “Maintain basic device protection,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.

Stop when a party demands remote control, verification codes, a seed phrase or private key, or promises asset recovery in exchange for credentials or signatures. Legitimate support does not need wallet secrets. In the context of “Maintain basic device protection,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. A useful security model covers the entire path from credentials and device state to website identity, request details and the final on-chain result. Protecting only one layer leaves other attack surfaces unexamined.

The goal for “Maintain basic device protection” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.

  • Keep seed phrases and private keys offline and private
  • Never send recovery material or verification codes
  • Review transfers and signatures item by item
  • Stop new transfers and approvals after suspicious activity

Common mistakes and a better sequence

If “Maintain basic device protection” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.

Be cautious with public Wi-Fi and shared computers

Shared environments can add interception, shoulder-surfing, browser-residue or malware risk and are poor choices for wallet recovery or high-value actions. Device security includes updates, screen locks, software sources, clipboard behavior, remote-control access and the risks of public computers or networks. For “Be cautious with public Wi-Fi and shared computers,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.

After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action. In the context of “Be cautious with public Wi-Fi and shared computers,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action.

The goal for “Be cautious with public Wi-Fi and shared computers” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.

  • Keep seed phrases and private keys offline and private
  • Never send recovery material or verification codes
  • Review transfers and signatures item by item
  • Stop new transfers and approvals after suspicious activity

Building the check into routine use

If “Be cautious with public Wi-Fi and shared computers” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.

Clipboard and screen content can leak too

After copying an address, verify it again rather than trusting the clipboard, and avoid exposing sensitive data or signature details during screen sharing. Device security includes updates, screen locks, software sources, clipboard behavior, remote-control access and the risks of public computers or networks. For “Clipboard and screen content can leak too,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.

Stop when a party demands remote control, verification codes, a seed phrase or private key, or promises asset recovery in exchange for credentials or signatures. Legitimate support does not need wallet secrets. In the context of “Clipboard and screen content can leak too,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. A useful security model covers the entire path from credentials and device state to website identity, request details and the final on-chain result. Protecting only one layer leaves other attack surfaces unexamined.

The goal for “Clipboard and screen content can leak too” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.

  • Keep seed phrases and private keys offline and private
  • Never send recovery material or verification codes
  • Review transfers and signatures item by item
  • Stop new transfers and approvals after suspicious activity

How to verify the result

If “Clipboard and screen content can leak too” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.

Treat remote-control requests as a major warning

Legitimate support does not need remote control to inspect a seed phrase or sign on the user’s behalf; end such sessions and review device security. Device security includes updates, screen locks, software sources, clipboard behavior, remote-control access and the risks of public computers or networks. For “Treat remote-control requests as a major warning,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.

A useful security model covers the entire path from credentials and device state to website identity, request details and the final on-chain result. Protecting only one layer leaves other attack surfaces unexamined. In the context of “Treat remote-control requests as a major warning,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. Stop when a party demands remote control, verification codes, a seed phrase or private key, or promises asset recovery in exchange for credentials or signatures. Legitimate support does not need wallet secrets.

The goal for “Treat remote-control requests as a major warning” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.

  • Keep seed phrases and private keys offline and private
  • Never send recovery material or verification codes
  • Review transfers and signatures item by item
  • Stop new transfers and approvals after suspicious activity

Common mistakes and a better sequence

If “Treat remote-control requests as a major warning” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.