imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Distinguish message signatures, transaction signatures and risky requests

Signature Requests

A signature may only prove account control, or it may authorize asset-related activity. Do not approve what you do not understand. The page moves from fundamentals and workflow to verification and risk checks.

Core principleA signature may only prove account control, or it may authorize asset-related activity. Do not approve what you do not understand.

Never send a seed phrase, private key or verification code to anyone.

Start with clear boundaries

The most important first step in Signature Requests is understanding which facts come from the wallet interface, which come from the blockchain, and which depend on a third-party service. Treating these as separate layers helps prevent a temporary display state from being mistaken for a final on-chain result.

Prefer information that can be independently checked: the network, destination address, transaction hash, contract address, approval target or validator state. Familiar branding or polished interface language is not a substitute for verification.

For Signature Requests, keep the network, account, target and outcome as separate checkpoints. If a balance display changes, a transaction is pending or a third-party page behaves unexpectedly, start with public on-chain facts instead of repeating a signature or sending again.

Understand the lifecycle of an action

A practical way to reason about Signature Requests is to separate an action into preparation, request, wallet confirmation, network processing and final verification. Problems that look similar on screen can originate at very different stages, from a wrong parameter to congestion or a third-party application issue.

Many on-chain actions are difficult or impossible for a wallet to reverse on its own. Reviewing the summary, network and destination before submission is therefore more reliable than looking for a remedy afterward.

A message signature may be used for login or proof of account control, while a transaction signature can change blockchain state. Some structured signatures may also carry permission implications, so read the visible fields and intended purpose.

If the content is blank, confusing, unrelated to the action you initiated or presented by an unfamiliar site, reject it and verify the source before continuing.

For Signature Requests, keep the network, account, target and outcome as separate checkpoints. If a balance display changes, a transaction is pending or a third-party page behaves unexpectedly, start with public on-chain facts instead of repeating a signature or sending again.

Build security into the workflow

Security should be part of every stage of Signature Requests, not a warning shown at the end. For any request involving a key, signature, approval or transfer, ask who is making the request, what permission is being requested, what it can affect and whether it can later be revoked.

Seed phrases and private keys remain under the user’s control. imtoken personnel will not ask for them. Never send a seed phrase, private key or verification code to anyone, and be cautious with urgency, remote-control requests or unfamiliar links.

For Signature Requests, keep the network, account, target and outcome as separate checkpoints. If a balance display changes, a transaction is pending or a third-party page behaves unexpectedly, start with public on-chain facts instead of repeating a signature or sending again.

Practical checklist

  • Verify the network and destination
  • Read the signature or approval target
  • Keep non-sensitive data such as transaction hashes

Verify the outcome independently

After a Signature Requests action, do not rely on a single success message. Check the transaction hash, explorer status, network and destination address. For approvals, also review the approved contract and allowance to confirm that the final permission matches what you intended.

If the outcome is unclear, keep non-sensitive diagnostic information such as the transaction hash, network name and sequence of steps. A seed phrase, private key or verification code is never appropriate troubleshooting material.

For Signature Requests, keep the network, account, target and outcome as separate checkpoints. If a balance display changes, a transaction is pending or a third-party page behaves unexpectedly, start with public on-chain facts instead of repeating a signature or sending again.

imtoken

Make on-chain decisions with clearer context

Downloads are provided through the site’s unified entry. Review every transfer, signature and approval independently before continuing.

Download imtoken