imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken
Home / Phishing & Scams
imtoken

Phishing & Scams

Recognize look-alike domains, fake support, fake airdrops and urgency-based manipulation.

Understand the core relationships in Phishing & Scams

Recognize look-alike domains, fake support, fake airdrops and urgency-based manipulation. In this topic, look-alike domain, fake support and fake airdrop should be understood as connected parts of the same on-chain workflow. A wallet interface is a view and signing tool, while the actual outcome still depends on the selected network, destination, contract rules and block confirmation.

When building a reliable routine for Phishing & Scams, include countdown and unknown link in the same review path. A display delay, pending state or third-party prompt should be checked against public chain data and the active network before you repeat a transaction, signature or approval.

A practical Phishing & Scams workflow

A practical sequence starts by confirming look-alike domain and fake support, checking that fake airdrop matches the intended action, reviewing the information related to countdown, and keeping unknown link for later verification. This order reduces mistakes caused by look-alike addresses, network changes, cached interfaces or misleading third-party prompts.

If a DApp or smart contract is involved, treat connection, message signing, transaction signing and token approval as separate actions. A successful connection does not make later requests trustworthy. Review every request on its own and remove sessions or permissions that are no longer needed.

Risk and verification points

Risk often comes from skipping a small detail: trusting a label without checking look-alike domain, copying a destination without confirming fake support, ignoring fake airdrop, or approving a request related to countdown that you cannot explain. Familiar-looking screens are not a substitute for verifying the network, address, contract and permission.

The security rules remain consistent: users keep seed phrases and private keys under their own control; legitimate support does not request them or verification codes. Confirmed blockchain transactions are generally not reversible by a wallet, and third-party DApps and smart contracts can introduce technical, operational or phishing risk.

How to verify outcomes independently

To verify a Phishing & Scams outcome independently, use the public address, the correct network explorer and verifiable information such as unknown link. If the wallet display differs from chain data, check the active network, node or indexing state before taking another asset-moving action.

When information conflicts, prefer a reputable block explorer, protocol documentation and a trusted saved entry point over search ads, unsolicited social messages, unknown support accounts or look-alike domains. For staking and validator services, also evaluate waiting time, fees, contract risk and market volatility.

On this page
  1. Understand the core relationships in Phishing & Scams
  2. A practical Phishing & Scams workflow
  3. Risk and verification points
  4. How to verify outcomes independently

Continue learning and verifying

Before any on-chain action, check the network, destination, amount and request details. Third-party DApps and smart contracts may carry risk.

Download imtoken