imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Security

Seed Phrase & Private Keys

This guide focuses on Seed Phrase & Private Keys and is designed to distinguish seed phrases from private keys in purpose, backup boundaries and recovery scenarios rather than treating them like ordinary passwords. It follows a practical sequence from concepts and checks to risk review and post-action verification.

Security center
Offline wallet key safety illustration
Core principles

For Seed Phrase & Private Keys, keep seed phrases and private keys under your own control; no one should ask for them; review each transfer, signature and approval separately.

Seed phrases

Start with a verifiable understanding of Seed phrases, then place it back into the complete Seed Phrase & Private Keys workflow.

Practical checks for Seed phrases

For Seed Phrase & Private Keys, Within the Seed Phrase & Private Keys workflow, A seed phrase is a highly sensitive recovery secret that can derive or restore a set of keys. It should not be treated like a normal login password or a support verification code. The useful question is not simply “what does Seed phrases mean?” but which network, account or contract it refers to and what on-chain state it can change.

A reviewable process is: keep a seed phrase complete, private and offline when it is used to recover a key set; a private key directly controls its address and should also stay out of untrusted environments. At each stage, retain public evidence such as the network name, address, transaction hash, contract address or block state. Those facts are sufficient for most diagnosis without exposing recovery secrets.

Risk analysis should stay specific to this step. screenshots, plaintext cloud storage, chat forwarding, shared printers and unknown recovery pages can leave durable copies of secrets. If the interface and the expected result disagree, stop before taking another action and recover only in a trusted wallet workflow and verify that restored addresses match the expected backup; familiarity, urgency or a previous connection is not a reason to skip a fresh check.

  • Confirm the network, account or contract associated with Seed phrases
  • Before and after the action, recover only in a trusted wallet workflow and verify that restored addresses match the expected backup
  • Never provide a seed phrase, private key or verification code in order to resolve Seed phrases

Private keys

Start with a verifiable understanding of Private keys, then place it back into the complete Seed Phrase & Private Keys workflow.

Practical checks for Private keys

For Seed Phrase & Private Keys, Private keys connects the conceptual explanation to a real wallet action. A private key directly enables signatures for its address. Public addresses can be shared for receiving, but private keys should never be handed over for troubleshooting, identity checks or promotions. The practical distinction is between information that can safely be verified in public and credentials that provide control and therefore must remain private.

For the workflow itself, keep a seed phrase complete, private and offline when it is used to recover a key set; a private key directly controls its address and should also stay out of untrusted environments. If the network, address, permission or state becomes inconsistent, return to that point rather than clicking repeatedly or submitting another request, because a display problem should not be turned into a second on-chain action.

A common mistake is trusting the front end without reconciling it with chain state. screenshots, plaintext cloud storage, chat forwarding, shared printers and unknown recovery pages can leave durable copies of secrets. A stronger approach is to recover only in a trusted wallet workflow and verify that restored addresses match the expected backup and re-check the intended outcome before any signature, approval or transfer.

  • Confirm the network, account or contract associated with Private keys
  • Before and after the action, recover only in a trusted wallet workflow and verify that restored addresses match the expected backup
  • Never provide a seed phrase, private key or verification code in order to resolve Private keys

Offline backups

Start with a verifiable understanding of Offline backups, then place it back into the complete Seed Phrase & Private Keys workflow.

Practical checks for Offline backups

For Seed Phrase & Private Keys, Understanding Offline backups requires both its technical meaning and its operational consequence. An offline backup reduces exposure to cloud sync, screenshot tools, chat applications and malware while still requiring the record to remain complete, readable and physically protected. That is why the same button label, address shape or asset name can mean different things on another network, contract or permission context.

Break the task into four stages—verify origin, verify network, verify target, verify outcome—and apply this page’s workflow: keep a seed phrase complete, private and offline when it is used to recover a key set; a private key directly controls its address and should also stay out of untrusted environments. This order catches many visible errors before a request becomes an on-chain state change.

Do not assume that “nothing moved yet” means “there is no risk.” screenshots, plaintext cloud storage, chat forwarding, shared printers and unknown recovery pages can leave durable copies of secrets. Reject or exit requests you cannot explain, then recover only in a trusted wallet workflow and verify that restored addresses match the expected backup; once confirmed, on-chain transactions generally cannot be reversed by the wallet alone.

  • Confirm the network, account or contract associated with Offline backups
  • Before and after the action, recover only in a trusted wallet workflow and verify that restored addresses match the expected backup
  • Never provide a seed phrase, private key or verification code in order to resolve Offline backups

Safe recovery

Start with a verifiable understanding of Safe recovery, then place it back into the complete Seed Phrase & Private Keys workflow.

Practical checks for Safe recovery

For Seed Phrase & Private Keys, Safe recovery is also part of the post-action verification path for this topic. Recovery means importing an existing secret into a trusted wallet environment and confirming the expected addresses and history; it should not involve uploading the secret to a website for “verification.” It lets a user map an interface message back to independently checkable network state rather than relying on one success, failure or loading indicator.

Continue checking after the initial action: keep a seed phrase complete, private and offline when it is used to recover a key set; a private key directly controls its address and should also stay out of untrusted environments. Cross-network transfers, contract calls, approvals and staking can include several stages, so the first status message may not describe the final outcome.

When the result differs from expectation, preserve public evidence and stop new signatures or transfers. screenshots, plaintext cloud storage, chat forwarding, shared printers and unknown recovery pages can leave durable copies of secrets. Then recover only in a trusted wallet workflow and verify that restored addresses match the expected backup before deciding whether to wait, retry or change the next step.

  • Confirm the network, account or contract associated with Safe recovery
  • Before and after the action, recover only in a trusted wallet workflow and verify that restored addresses match the expected backup
  • Never provide a seed phrase, private key or verification code in order to resolve Safe recovery