imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Web3 & DApps

Signature Requests

Distinguishing message signatures, transaction signatures and risky requests

Understand the relationship between message signatures and transaction signatures

Many wallet mistakes are not caused by one button; they happen because the surrounding context is misunderstood. When reviewing message signatures, also check the active network, address, asset type and the request in front of you. transaction signatures often depends on the step before or after it, so treating one field in isolation can hide important risk. imtoken focuses on explaining these relationships rather than replacing judgment with slogans.

For Signature Requests, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Message signatures should be understood together with transaction signatures; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with message signatures.
  • Review the destination or contract related to transaction signatures.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Check transaction signatures before you act

Before an action involving transaction signatures, answer three questions: which network is active, who or what is the destination, and what on-chain result will this request create? If request details is also involved, review the fee asset, permission scope or confirmation state. Once a transaction is broadcast, the network rules usually determine what can happen next, which makes pre-confirmation checks especially valuable.

For Signature Requests, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Transaction signatures should be understood together with request details; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with transaction signatures.
  • Review the destination or contract related to request details.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Place request details in the full on-chain workflow

Placing request details inside the full workflow makes its purpose easier to understand. A typical path includes selecting a network, verifying an address or contract, reviewing request details, checking fees, broadcasting and waiting for confirmation. domain checks may affect one or several of those stages. Knowing exactly where it matters helps you decide whether a prompt is expected and whether the result matches your intent.

For Signature Requests, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Request details should be understood together with domain checks; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with request details.
  • Review the destination or contract related to domain checks.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Common mistakes and risk signals

Warning signs include pressure to act immediately, a domain that does not match what you expected, an unexplained network switch, an unfamiliar approval target, an allowance much larger than necessary, a pasted address that changes, or anyone asking for a seed phrase or private key. For requests involving domain checks or malicious signatures, return to your original purpose and verify the on-chain details rather than relying on verbal assurances.

For Signature Requests, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Domain checks should be understood together with malicious signatures; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with domain checks.
  • Review the destination or contract related to malicious signatures.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Build a repeatable review habit

A repeatable sequence reduces missed details: verify the entry point and domain, confirm the account and network, check the destination, amount or contract parameters, then review fees, signatures and approvals. Afterward, inspect the transaction hash and status, and remove connections or approvals you no longer use. The same sequence works for malicious signatures and helps place message signatures in a practical routine.

For Signature Requests, a useful way to judge the situation is to compare the request with your intended outcome. If the screen asks for something broader than the task requires, stop and review the details. Malicious signatures should be understood together with message signatures; the combination often explains why a fee changes, why a transaction is still pending, or why a permission deserves another look.

Practical checks

  • Confirm the active network before working with malicious signatures.
  • Review the destination or contract related to message signatures.
  • Do not share a seed phrase, private key or verification code.
  • Keep the transaction hash when an on-chain action is submitted.

Related reading

imtoken

Keep the next step clear

Review the network, address and request details before you continue. Use the official download entry when you are ready.

Download imtoken