imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Wallet & Assets

imtoken Web

imtoken Web explains browser connections, account selection, signature review and approvals and disconnection with practical wallet, network and Web3 checks.

imtokenMulti-chain assets and Web3 hub

01

Browser connections

Security around browser connections should be considered together with seed phrases, private keys, device conditions and permission management. Transaction hashes, block height, contract addresses and event logs provide useful verification points for distinguishing interface delays from actual on-chain state. A legitimate workflow does not require sending recovery secrets or verification codes to another person or entering them into an unknown webpage.

For browser connections, begin by identifying the active network, the exact address or contract involved, and the result you actually intend to achieve. Separate chains maintain separate state, and similar-looking address formats do not make networks interchangeable; use the correct block explorer when you need public verification. This turns an interface prompt into information that can be independently checked instead of relying on a name, icon or single status label.

More broadly, browser connections rarely stands alone. It usually connects to at least one of the following: an address, an active network, gas, a transaction hash, a DApp request or validator state. Reading those pieces together reduces errors caused by choosing the wrong chain, misunderstanding a permission or misreading a pending state.

Verify the active network, address or contract targetKeep a transaction hash or other public data that can be independently checkedNever provide a seed phrase, private key or verification code to anyone

02

Account selection

For account selection, begin by identifying the active network, the exact address or contract involved, and the result you actually intend to achieve. Connections, message signatures, transaction signatures and token approvals are distinct requests; review the spender, allowance and expected effect separately. This turns an interface prompt into information that can be independently checked instead of relying on a name, icon or single status label.

A practical review of account selection separates origin, target, permission or value, and network state. Transaction hashes, block height, contract addresses and event logs provide useful verification points for distinguishing interface delays from actual on-chain state. If a contract is unfamiliar, an allowance is unexpectedly broad, the network is wrong, or the result does not match your intent, stop and verify the transaction hash, contract address or block state before continuing.

More broadly, account selection rarely stands alone. It usually connects to at least one of the following: an address, an active network, gas, a transaction hash, a DApp request or validator state. Reading those pieces together reduces errors caused by choosing the wrong chain, misunderstanding a permission or misreading a pending state.

Verify the active network, address or contract targetKeep a transaction hash or other public data that can be independently checkedNever provide a seed phrase, private key or verification code to anyone

03

Signature review

A practical review of signature review separates origin, target, permission or value, and network state. Connections, message signatures, transaction signatures and token approvals are distinct requests; review the spender, allowance and expected effect separately. If a contract is unfamiliar, an allowance is unexpectedly broad, the network is wrong, or the result does not match your intent, stop and verify the transaction hash, contract address or block state before continuing.

Understanding signature review also means considering what remains true after you confirm. Transaction hashes, block height, contract addresses and event logs provide useful verification points for distinguishing interface delays from actual on-chain state. On-chain transactions generally cannot be reversed by a wallet alone, and a DApp connection is not the same as an approval. The confirmation button is only the final step; the important work happens before it.

More broadly, signature review rarely stands alone. It usually connects to at least one of the following: an address, an active network, gas, a transaction hash, a DApp request or validator state. Reading those pieces together reduces errors caused by choosing the wrong chain, misunderstanding a permission or misreading a pending state.

Verify the active network, address or contract targetKeep a transaction hash or other public data that can be independently checkedNever provide a seed phrase, private key or verification code to anyone

04

Approvals and disconnection

Understanding approvals and disconnection also means considering what remains true after you confirm. Connections, message signatures, transaction signatures and token approvals are distinct requests; review the spender, allowance and expected effect separately. On-chain transactions generally cannot be reversed by a wallet alone, and a DApp connection is not the same as an approval. The confirmation button is only the final step; the important work happens before it.

Security around approvals and disconnection should be considered together with seed phrases, private keys, device conditions and permission management. Transaction hashes, block height, contract addresses and event logs provide useful verification points for distinguishing interface delays from actual on-chain state. A legitimate workflow does not require sending recovery secrets or verification codes to another person or entering them into an unknown webpage.

More broadly, approvals and disconnection rarely stands alone. It usually connects to at least one of the following: an address, an active network, gas, a transaction hash, a DApp request or validator state. Reading those pieces together reduces errors caused by choosing the wrong chain, misunderstanding a permission or misreading a pending state.

Verify the active network, address or contract targetKeep a transaction hash or other public data that can be independently checkedNever provide a seed phrase, private key or verification code to anyone