Core Security Principles

Approval Security & Risk Checks is easier to use safely when you separate what the wallet interface shows from what the blockchain actually records. In practice, you should consider 授权对象, 授权额度, and 无限授权 together. A wallet can prepare and broadcast a request, but the final state is determined by the selected network and the transaction that network accepts.

Before taking action, confirm that 授权额度 matches what you intend to do, then review 无限授权 and 取消授权. If a page, DApp, or third-party service asks for a seed phrase, private key, recovery phrase, or verification code, stop. imtoken will not ask you to disclose those secrets, and they should never be sent to another person.

Blockchain actions are often difficult or impossible for a wallet provider to reverse on its own. When evaluating 无限授权, prefer verifiable information such as the network name, destination address, transaction hash, contract address, and block explorer records instead of relying only on screenshots, chat messages, or unfamiliar links.

If something looks wrong around DApp, avoid repeatedly submitting the same action. Record the network, address, and transaction hash first, then determine whether the request was broadcast, is waiting for confirmation, or failed because of fees or parameters. Repeated attempts can add cost and make troubleshooting harder.

The practical goal here is to 减少不必要的长期权限并定期检查历史授权. When information cannot be verified, pause and return to on-chain records or official pages instead of relying on someone else's assurance.

Recognizing High-risk Situations

Before taking action, confirm that 授权额度 matches what you intend to do, then review 无限授权 and 取消授权. If a page, DApp, or third-party service asks for a seed phrase, private key, recovery phrase, or verification code, stop. imtoken will not ask you to disclose those secrets, and they should never be sent to another person.

Blockchain actions are often difficult or impossible for a wallet provider to reverse on its own. When evaluating 无限授权, prefer verifiable information such as the network name, destination address, transaction hash, contract address, and block explorer records instead of relying only on screenshots, chat messages, or unfamiliar links.

If something looks wrong around DApp, avoid repeatedly submitting the same action. Record the network, address, and transaction hash first, then determine whether the request was broadcast, is waiting for confirmation, or failed because of fees or parameters. Repeated attempts can add cost and make troubleshooting harder.

For 授权对象, a repeatable review order is useful: verify the source, verify the network, verify the counterparty or contract, review the requested permission, check the amount, and only then decide whether to sign or send. A stable checklist makes subtle differences easier to notice.

The practical goal here is to 减少不必要的长期权限并定期检查历史授权. When information cannot be verified, pause and return to on-chain records or official pages instead of relying on someone else's assurance.

Verification order

Verify the source and network first, then the address, amount, requested permission and fees; finally review the transaction hash or on-chain state.

What to Do When Something Looks Wrong

Blockchain actions are often difficult or impossible for a wallet provider to reverse on its own. When evaluating 无限授权, prefer verifiable information such as the network name, destination address, transaction hash, contract address, and block explorer records instead of relying only on screenshots, chat messages, or unfamiliar links.

If something looks wrong around DApp, avoid repeatedly submitting the same action. Record the network, address, and transaction hash first, then determine whether the request was broadcast, is waiting for confirmation, or failed because of fees or parameters. Repeated attempts can add cost and make troubleshooting harder.

For 授权对象, a repeatable review order is useful: verify the source, verify the network, verify the counterparty or contract, review the requested permission, check the amount, and only then decide whether to sign or send. A stable checklist makes subtle differences easier to notice.

Approval Security & Risk Checks is easier to use safely when you separate what the wallet interface shows from what the blockchain actually records. In practice, you should consider 恶意合约, 授权对象, and 授权额度 together. A wallet can prepare and broadcast a request, but the final state is determined by the selected network and the transaction that network accepts.

The practical goal here is to 减少不必要的长期权限并定期检查历史授权. When information cannot be verified, pause and return to on-chain records or official pages instead of relying on someone else's assurance.

When something looks wrong

Do not keep clicking or resubmitting. Preserve information that can be safely verified, and never provide a seed phrase, private key, verification code, or remote-control access.

A Repeatable Safety Checklist

If something looks wrong around DApp, avoid repeatedly submitting the same action. Record the network, address, and transaction hash first, then determine whether the request was broadcast, is waiting for confirmation, or failed because of fees or parameters. Repeated attempts can add cost and make troubleshooting harder.

For 授权对象, a repeatable review order is useful: verify the source, verify the network, verify the counterparty or contract, review the requested permission, check the amount, and only then decide whether to sign or send. A stable checklist makes subtle differences easier to notice.

Approval Security & Risk Checks is easier to use safely when you separate what the wallet interface shows from what the blockchain actually records. In practice, you should consider 恶意合约, 授权对象, and 授权额度 together. A wallet can prepare and broadcast a request, but the final state is determined by the selected network and the transaction that network accepts.

Before taking action, confirm that 授权对象 matches what you intend to do, then review 授权额度 and 无限授权. If a page, DApp, or third-party service asks for a seed phrase, private key, recovery phrase, or verification code, stop. imtoken will not ask you to disclose those secrets, and they should never be sent to another person.

The practical goal here is to 减少不必要的长期权限并定期检查历史授权. When information cannot be verified, pause and return to on-chain records or official pages instead of relying on someone else's assurance.