imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Security

Phishing & Scams

Recognizing fake sites, support scams, fake airdrops and malicious signing prompts

Understand the relationship between phishing sites and fake support

Many wallet mistakes are not caused by one button; they happen because the surrounding context is misunderstood. When reviewing phishing sites, also check the active network, address, asset type and the request in front of you. fake support often depends on the step before or after it, so treating one field in isolation can hide important risk. imtoken focuses on explaining these relationships rather than replacing judgment with slogans.

For Phishing & Scams, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Phishing sites should be understood together with fake support; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with phishing sites.
  • Review the destination or contract related to fake support.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Check fake support before you act

Before an action involving fake support, answer three questions: which network is active, who or what is the destination, and what on-chain result will this request create? If fake airdrops is also involved, review the fee asset, permission scope or confirmation state. Once a transaction is broadcast, the network rules usually determine what can happen next, which makes pre-confirmation checks especially valuable.

For Phishing & Scams, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Fake support should be understood together with fake airdrops; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with fake support.
  • Review the destination or contract related to fake airdrops.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Place fake airdrops in the full on-chain workflow

Placing fake airdrops inside the full workflow makes its purpose easier to understand. A typical path includes selecting a network, verifying an address or contract, reviewing request details, checking fees, broadcasting and waiting for confirmation. clipboard attacks may affect one or several of those stages. Knowing exactly where it matters helps you decide whether a prompt is expected and whether the result matches your intent.

For Phishing & Scams, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Fake airdrops should be understood together with clipboard attacks; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with fake airdrops.
  • Review the destination or contract related to clipboard attacks.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Common mistakes and risk signals

Warning signs include pressure to act immediately, a domain that does not match what you expected, an unexplained network switch, an unfamiliar approval target, an allowance much larger than necessary, a pasted address that changes, or anyone asking for a seed phrase or private key. For requests involving clipboard attacks or remote-control scams, return to your original purpose and verify the on-chain details rather than relying on verbal assurances.

For Phishing & Scams, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Clipboard attacks should be understood together with remote-control scams; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with clipboard attacks.
  • Review the destination or contract related to remote-control scams.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Build a repeatable review habit

A repeatable sequence reduces missed details: verify the entry point and domain, confirm the account and network, check the destination, amount or contract parameters, then review fees, signatures and approvals. Afterward, inspect the transaction hash and status, and remove connections or approvals you no longer use. The same sequence works for remote-control scams and helps place phishing sites in a practical routine.

For Phishing & Scams, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Remote-control scams should be understood together with phishing sites; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with remote-control scams.
  • Review the destination or contract related to phishing sites.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Related reading

imtoken

Keep the next step clear

Review the network, address and request details before you continue. Use the official download entry when you are ready.

Download imtoken