On this pagePhishing domains and imitation pagesFake support and remote assistanceFake airdrops and malicious QR codesDamage-control steps after suspicious activity

Phishing domains and imitation pages

For phishing domains and imitation pages, the goal is not to memorize labels but to build a repeatable decision sequence: confirm the current network and account context, understand what the requested action changes, and then verify the resulting state on-chain. Security is about reducing unnecessary exposure and single points of failure rather than promising absolute protection. Seed phrases and private keys are controlled by the user. Official personnel should never ask for them, and they should not be shared through chat, email, web forms, screenshots or cloud documents. Phishing domains and imitation pages also connects to other wallet tasks. Network choice affects fees and transaction visibility, contract interaction can affect approvals and asset state, and security habits apply across creation, backup, transfers and Web3 use. Scams are commonly distributed through search ads, imitation domains, direct messages and fake support channels. A strong defense is an independent verification path rather than evidence supplied by the person asking you to act.

Fake support and remote assistance

For fake support and remote assistance, the goal is not to memorize labels but to build a repeatable decision sequence: confirm the current network and account context, understand what the requested action changes, and then verify the resulting state on-chain. High-risk situations often use urgency, familiar branding or a routine-looking signing flow. For airdrops, support claims, verification, refunds or recovery promises, independently check the domain, contract address, network and exact request. Unknown links, QR codes, browser extensions and remote-control tools can all increase risk. When something looks wrong, break fake support and remote assistance into four questions: what address or contract is involved, which network is active, what action is being requested, and what result should be visible on-chain. This is usually more reliable than repeating the same click. Scams are commonly distributed through search ads, imitation domains, direct messages and fake support channels. A strong defense is an independent verification path rather than evidence supplied by the person asking you to act.

A practical review sequence

  1. Confirm the active network and the intended account
  2. Verify the address, contract or DApp source
  3. Read the exact action, amount and permission scope
  4. Verify the public on-chain result after completion

Fake airdrops and malicious QR codes

For fake airdrops and malicious qr codes, the goal is not to memorize labels but to build a repeatable decision sequence: confirm the current network and account context, understand what the requested action changes, and then verify the resulting state on-chain. On-chain transactions and approvals have real consequences. Verify the address, network and amount before sending; identify whether a prompt is a message signature or a transaction; and check the spender and allowance before approving a token. Revoke permissions you no longer need and treat third-party DApps and contracts as independent risk sources. For an unfamiliar fake airdrops and malicious qr codes issue, keep verifiable non-sensitive evidence such as a public address, network name, transaction hash and visible error text. Sensitive credentials are not troubleshooting material and should not be given to support staff. Scams are commonly distributed through search ads, imitation domains, direct messages and fake support channels. A strong defense is an independent verification path rather than evidence supplied by the person asking you to act.

Security note: imtoken will never ask for a seed phrase, private key or verification code. A wallet provider also cannot unilaterally reverse a completed on-chain transaction.

Damage-control steps after suspicious activity

For damage-control steps after suspicious activity, the goal is not to memorize labels but to build a repeatable decision sequence: confirm the current network and account context, understand what the requested action changes, and then verify the resulting state on-chain. Security is about reducing unnecessary exposure and single points of failure rather than promising absolute protection. Seed phrases and private keys are controlled by the user. Official personnel should never ask for them, and they should not be shared through chat, email, web forms, screenshots or cloud documents. Damage-control steps after suspicious activity also connects to other wallet tasks. Network choice affects fees and transaction visibility, contract interaction can affect approvals and asset state, and security habits apply across creation, backup, transfers and Web3 use. Scams are commonly distributed through search ads, imitation domains, direct messages and fake support channels. A strong defense is an independent verification path rather than evidence supplied by the person asking you to act.

Final checklist

✓ Keep seed phrases offline✓ Never disclose private keys✓ Verify address and network✓ Read signature requests✓ Review token approvals✓ Use trusted devices and networks