imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Updates

Product, Network & Security Notices

Product behavior, network verification, security principles, and service mechanics are presented without invented dates, partnerships, financing claims, user counts, or market rankings.

Recent Update · Product

A verification sequence for assets and networks

Start by confirming the active blockchain network before interpreting a balance, token contract, or transaction record. Before sending, re-check the recipient address, network, amount, and gas. After submission, keep the transaction hash and inspect execution and confirmation status with a block explorer for the same network.

Asset names and icons are useful labels, but they are not substitutes for on-chain identifiers. When a token name is duplicated across networks, a transaction has just been submitted, or the wallet has recently switched networks, compare the network, contract address, and transaction hash before taking another action.

Network Notice

Identify the asset's current chain before cross-network or Layer 2 actions

Similar address formats do not make assets automatically portable across chains. A cross-network or cross-layer transfer normally depends on a supported bridge or service route and may involve source-network fees, destination confirmations, exit waiting periods, and different representations of an asset.

Before starting, identify the source chain, intended destination chain, and the contract or service responsible for the route. Afterward, check records on both sides when applicable rather than relying only on a single interface message that says an operation is complete.

Security Notice

No one should ask for your seed phrase, private key, or verification code

imtoken will never ask for a seed phrase, private key, or verification code. Stop when someone claiming to be support, an administrator, an airdrop operator, or a security specialist asks for secret recovery material, requests remote-control software, or directs you to enter a recovery phrase on an unfamiliar page.

Security checks also include the domain, device, and transaction details. Look-alike domains, clipboard address replacement, public computers, public Wi-Fi, and unverified browser extensions can increase exposure. Reopen a trusted entry point and verify the address and network before important actions.

Service Notice

Understand PoS validators, rewards, and exits

Proof-of-stake participation involves validator status, reward sources, network penalties, withdrawal mechanics, and exit queues. Staking does not assure returns, rewards can change with network rules and conditions, and an exit may involve a waiting period.

When a third-party service is involved, also understand service fees, custody arrangements, smart-contract exposure, and operational risk. Digital-asset prices can fluctuate independently of protocol rewards, so participation should be assessed against technical, liquidity, and market risks rather than a historical yield figure alone.

Product Note

Treat DApp connection, signing, and approval as separate decisions

Connecting a DApp usually establishes a session between an account and a site; it does not approve every later action. Message signatures, transaction signatures, token approvals, and smart-contract interactions have different effects and should be reviewed independently.

Before approving, inspect the spender, token, allowance, and network. Before signing, verify the domain, account, and request details. Disconnect sessions you no longer use and consider revoking permissions that are no longer needed. Third-party DApps and smart contracts can carry their own risks.