Seed phrases and private keys remain under user control
Recovery material represents account control and should never be sent to supposed support staff, partners, airdrop pages or other people; legitimate imtoken personnel will not request it. Wallet security combines key custody, device hygiene, network verification and permission habits; no single feature justifies an absolute security promise. For “Seed phrases and private keys remain under user control,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.
After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action. In the context of “Seed phrases and private keys remain under user control,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action.
The goal for “Seed phrases and private keys remain under user control” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.
- Keep seed phrases and private keys offline and private
- Never send recovery material or verification codes
- Review transfers and signatures item by item
- Stop new transfers and approvals after suspicious activity
Building the check into routine use
If “Seed phrases and private keys remain under user control” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.
Signatures and approvals are frequent risk points
After connecting to a DApp, continue reviewing every signature and approval, especially the contract, permission scope, network and whether the request matches the intended action. Wallet security combines key custody, device hygiene, network verification and permission habits; no single feature justifies an absolute security promise. For “Signatures and approvals are frequent risk points,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.
A useful security model covers the entire path from credentials and device state to website identity, request details and the final on-chain result. Protecting only one layer leaves other attack surfaces unexamined. In the context of “Signatures and approvals are frequent risk points,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action.
The goal for “Signatures and approvals are frequent risk points” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.
- Keep seed phrases and private keys offline and private
- Never send recovery material or verification codes
- Review transfers and signatures item by item
- Stop new transfers and approvals after suspicious activity
Common mistakes and a better sequence
If “Signatures and approvals are frequent risk points” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.
Device and network conditions matter too
Public computers, public Wi-Fi, remote control, untrusted software and browser extensions can increase exposure and should be used cautiously. Wallet security combines key custody, device hygiene, network verification and permission habits; no single feature justifies an absolute security promise. For “Device and network conditions matter too,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.
After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action. In the context of “Device and network conditions matter too,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. After a suspicious event, stop new signatures and transfers, preserve verifiable facts such as transaction hashes, domains and contract addresses, then review approvals and the device environment before taking further action.
The goal for “Device and network conditions matter too” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.
- Keep seed phrases and private keys offline and private
- Never send recovery material or verification codes
- Review transfers and signatures item by item
- Stop new transfers and approvals after suspicious activity
Building the check into routine use
If “Device and network conditions matter too” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.
Pre- and post-transaction checks form a complete loop
Verify address, network, amount and gas before sending, then retain the transaction hash and inspect on-chain state instead of repeatedly submitting because an interface updates slowly. Wallet security combines key custody, device hygiene, network verification and permission habits; no single feature justifies an absolute security promise. For “Pre- and post-transaction checks form a complete loop,” first identify whether the relevant fact belongs to the local wallet interface, the selected network, or a contract permission. That distinction prevents an interface message from being mistaken for a final on-chain result.
A useful security model covers the entire path from credentials and device state to website identity, request details and the final on-chain result. Protecting only one layer leaves other attack surfaces unexamined. In the context of “Pre- and post-transaction checks form a complete loop,” use a consistent order: establish the account and network, inspect the specific address, contract or request parameters, and only then authorize an action that can move assets or create permissions. A useful security model covers the entire path from credentials and device state to website identity, request details and the final on-chain result. Protecting only one layer leaves other attack surfaces unexamined.
The goal for “Pre- and post-transaction checks form a complete loop” is to reduce exposure: do not transmit recovery material online, do not grant remote-control access to strangers, and do not let urgency bypass review. After a suspicious signature, inspect the account, approvals, transactions and device environment separately.
- Keep seed phrases and private keys offline and private
- Never send recovery material or verification codes
- Review transfers and signatures item by item
- Stop new transfers and approvals after suspicious activity
How to verify the result
If “Pre- and post-transaction checks form a complete loop” behaves differently from expected, record the active network, account, requester and any transaction hash, then eliminate possible causes one at a time. Do not keep signing, approving or sending assets merely to repair an issue that has not yet been identified.
