imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken Knowledge Center

Phishing & Scams|imtoken

Recognize look-alike domains, fake support, fake airdrops, urgency tactics and malicious signature prompts.

On this page

How phishing pages mimic trust

To understand Phishing & Scams, place how phishing pages mimic trust inside the full on-chain workflow instead of treating it as an isolated label. The practical point is to verify how phishing pages mimic trust in the context of the selected blockchain network. The user should compare the request with the intended address, asset, account or contract before confirming. A wallet can organize information and submit requests, but the selected network and the blockchain determine the final state. On-chain state and a transaction hash provide stronger evidence than a delayed interface alone. Third-party DApps, services and smart contracts can introduce risks that need separate review. If the interface does not match your expectation, verify the network, address, contract and on-chain record before taking another action.

A practical way to approach how phishing pages mimic trust is to use a consistent review sequence. First, the practical point is to verify how phishing pages mimic trust in the context of the selected blockchain network. Next, the user should compare the request with the intended address, asset, account or contract before confirming. After a transaction, signature or approval is submitted, on-chain state and a transaction hash provide stronger evidence than a delayed interface alone. Finally, third-party dapps, services and smart contracts can introduce risks that need separate review. This sequence gives each confirmation a clear reason and helps reduce wrong-network transfers, address mismatches, unnecessary permissions and repeated actions caused by a delayed interface.

  • The practical point is to verify how phishing pages mimic trust in the context of the selected blockchain network
  • The user should compare the request with the intended address, asset, account or contract before confirming
  • On-chain state and a transaction hash provide stronger evidence than a delayed interface alone
  • Third-party DApps, services and smart contracts can introduce risks that need separate review

Fake support tactics

To understand Phishing & Scams, place fake support tactics inside the full on-chain workflow instead of treating it as an isolated label. The practical point is to verify fake support tactics in the context of the selected blockchain network. The user should compare the request with the intended address, asset, account or contract before confirming. A wallet can organize information and submit requests, but the selected network and the blockchain determine the final state. On-chain state and a transaction hash provide stronger evidence than a delayed interface alone. Third-party DApps, services and smart contracts can introduce risks that need separate review. If the interface does not match your expectation, verify the network, address, contract and on-chain record before taking another action.

A practical way to approach fake support tactics is to use a consistent review sequence. First, the practical point is to verify fake support tactics in the context of the selected blockchain network. Next, the user should compare the request with the intended address, asset, account or contract before confirming. After a transaction, signature or approval is submitted, on-chain state and a transaction hash provide stronger evidence than a delayed interface alone. Finally, third-party dapps, services and smart contracts can introduce risks that need separate review. This sequence gives each confirmation a clear reason and helps reduce wrong-network transfers, address mismatches, unnecessary permissions and repeated actions caused by a delayed interface.

  • The practical point is to verify fake support tactics in the context of the selected blockchain network
  • The user should compare the request with the intended address, asset, account or contract before confirming
  • On-chain state and a transaction hash provide stronger evidence than a delayed interface alone
  • Third-party DApps, services and smart contracts can introduce risks that need separate review

Airdrop and approval traps

To understand Phishing & Scams, place airdrop and approval traps inside the full on-chain workflow instead of treating it as an isolated label. Approvals can give a contract permission to use tokens within a defined scope. The spender or operator address and amount should be checked before signing. A wallet can organize information and submit requests, but the selected network and the blockchain determine the final state. Disconnecting a DApp does not automatically revoke an on-chain approval. Unused permissions can be reviewed and revoked with a new on-chain transaction. If the interface does not match your expectation, verify the network, address, contract and on-chain record before taking another action.

A practical way to approach airdrop and approval traps is to use a consistent review sequence. First, approvals can give a contract permission to use tokens within a defined scope. Next, the spender or operator address and amount should be checked before signing. After a transaction, signature or approval is submitted, disconnecting a dapp does not automatically revoke an on-chain approval. Finally, unused permissions can be reviewed and revoked with a new on-chain transaction. This sequence gives each confirmation a clear reason and helps reduce wrong-network transfers, address mismatches, unnecessary permissions and repeated actions caused by a delayed interface.

  • Approvals can give a contract permission to use tokens within a defined scope
  • The spender or operator address and amount should be checked before signing
  • Disconnecting a DApp does not automatically revoke an on-chain approval
  • Unused permissions can be reviewed and revoked with a new on-chain transaction

When something feels suspicious

To understand Phishing & Scams, place when something feels suspicious inside the full on-chain workflow instead of treating it as an isolated label. The practical point is to verify when something feels suspicious in the context of the selected blockchain network. The user should compare the request with the intended address, asset, account or contract before confirming. A wallet can organize information and submit requests, but the selected network and the blockchain determine the final state. On-chain state and a transaction hash provide stronger evidence than a delayed interface alone. Third-party DApps, services and smart contracts can introduce risks that need separate review. If the interface does not match your expectation, verify the network, address, contract and on-chain record before taking another action.

A practical way to approach when something feels suspicious is to use a consistent review sequence. First, the practical point is to verify when something feels suspicious in the context of the selected blockchain network. Next, the user should compare the request with the intended address, asset, account or contract before confirming. After a transaction, signature or approval is submitted, on-chain state and a transaction hash provide stronger evidence than a delayed interface alone. Finally, third-party dapps, services and smart contracts can introduce risks that need separate review. This sequence gives each confirmation a clear reason and helps reduce wrong-network transfers, address mismatches, unnecessary permissions and repeated actions caused by a delayed interface.

  • The practical point is to verify when something feels suspicious in the context of the selected blockchain network
  • The user should compare the request with the intended address, asset, account or contract before confirming
  • On-chain state and a transaction hash provide stronger evidence than a delayed interface alone
  • Third-party DApps, services and smart contracts can introduce risks that need separate review
Download imtokenRead FAQ →