imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken

Recognizing Phishing and Scams

Recognize lookalike domains, fake support, fake airdrops, remote-assistance scams and clipboard replacement.

On this pageCore concepts and boundariesPractical use casesStep-by-step checksCommon misconceptionsSecurity checklistOngoing management
Core security principle

Seed phrases and private keys remain under the user’s control. Every transfer, signature and approval should be reviewed separately.

Core concepts and boundaries

To understand Recognizing Phishing and Scams, place phishing domain, fake support and fake airdrop in the same on-chain context. Recognize lookalike domains, fake support, fake airdrops, remote-assistance scams and clipboard replacement. A wallet interface organizes network information, but balances, transactions and contract state are still recorded by the relevant blockchain. Do not evaluate risk from a button label alone. Identify the active network, the target, the expected outcome and whether the request creates a signature, approval or on-chain fee. Any page or person asking for a seed phrase, private key or verification code should be rejected.

Practical use cases

In real use, phishing domain often appears together with fake support and remote control. A user may move from reading information to sending assets, connecting a DApp or calling a contract, and trust in the previous screen should not automatically extend to the next request. Separate verification into three layers: the source of the page, the exact wallet prompt, and the on-chain destination or contract effect. This reduces mistakes caused by familiar branding, time pressure or a sequence of prompts.

Step-by-step checks

For Recognizing Phishing and Scams, a repeatable workflow is useful. First verify phishing domain, then check fake support and fake airdrop, read the request related to remote control, and finally confirm whether clipboard matches the intended task. If the action is submitted on-chain, keep the transaction hash and verify the result with a trusted block explorer. If the action only creates a connection, remember that a session connection is different from a later signature or token approval. Stop when data, amounts or contract addresses are unclear.

Quick check
  • Verify phishing domain and fake support independently
  • Review fake airdrop and remote control in the wallet prompt
  • Never share seed phrases, private keys or verification codes

Common misconceptions

A common misconception is to treat a normal-looking interface as proof that the underlying action is safe. Correct-looking phishing domain does not guarantee that fake support is right, and a familiar fake airdrop label does not prove that the remote control address or contract is the expected one. Multi-chain environments make these mistakes easier because address formats, token names and page designs can look similar. Independent verification of the network, full address, contract and transaction status is more reliable than visual familiarity.

Define the taskVerify the network and targetRead the requestConfirm or stop

Security checklist

Keep high-privilege credentials separate from ordinary troubleshooting data. Seed phrases and private keys remain under the user’s control and should never be requested by support staff. Public information related to phishing domain, fake support or fake airdrop can often be used for diagnosis without exposing secrets. When remote control or clipboard is involved, also review the spender, allowance, domain, device environment and selected network. Blockchain transactions are generally not reversible by a wallet provider, so pre-confirmation checks matter most.

Ongoing management

Ongoing management of Recognizing Phishing and Scams means periodically reviewing networks, approvals, transaction history and connected services. Recognize lookalike domains, fake support, fake airdrops, remote-assistance scams and clipboard replacement. If a DApp or contract is no longer needed, disconnect the session and separately check whether any on-chain approval remains. If network rules, gas conditions or service status change, rely on current network data rather than assumptions from an earlier session. Security, confirmation time and staking outcomes should not be described as absolute guarantees.