imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Practical Guide

imtoken

Creating a wallet is only the start. Long-term access depends on backups, offline storage, recovery checks and private-key discipline.

01

Create versus import

Creating a wallet generates new key material, while importing restores control from an existing backup. Know which task you are performing before starting so that seed phrases are not overwritten, mixed up or copied unnecessarily. In practice, place “create versus import” back into the context of the active account, network and intended target instead of judging the action from interface styling or button labels alone.

02

Role of the seed phrase

A seed phrase is typically sensitive recovery material and exposure can allow another person to gain wallet control. It should not be photographed and uploaded, sent to support, pasted into chat tools or entered into a website unrelated to recovery. This is rarely solved safely by clicking through again. A repeatable verification order for role of the seed phrase is more reliable than trial and error.

03

How to back up offline

Use an offline medium you control and plan for loss, accidental destruction and unauthorized viewing. Keeping only one copy creates a single point of failure, while scattering copies across connected services increases the exposure surface. Treating how to back up offline as its own decision point helps prevent rapid click-through mistakes across multiple accounts, networks or DApp steps.

04

Verify the backup

After backing up, verify order, spelling and completeness without exposing the phrase to any third party. Do not use an unknown website to “check” whether a seed phrase is valid; the verification process itself should remain trusted and offline. The practical goal of verify the backup is to separate on-chain facts from interface presentation; if the two disagree, verify public blockchain state first.

05

Recovery environment

When restoring a wallet, use a trusted device and the correct official application entry. Avoid screen sharing, remote-control sessions and public computers. After recovery, verify the expected addresses, networks and account history. Because blockchain actions can create persistent or irreversible state, understanding recovery environment should come before signing, approving or submitting.

06

If a backup may be exposed

If a seed phrase or private key may have been seen by someone else, changing an app password alone does not remove key exposure. A safer response is to assess the risk, create a new secure wallet and move assets only after verifying the destination network and address. Reviewing if a backup may be exposed never requires giving anyone a seed phrase or private key; public state can be checked with addresses, transaction hashes and contract information.

Practical checklist

Use this list as a final review before you submit a transaction, signature or approval related to this topic.

  • Know whether you are creating or restoring
  • Keep backups only in offline locations you control
  • Verify seed phrase order and completeness
  • Disable screen sharing and remote control during recovery
  • Consider migration if key material may be exposed
Security boundary

Never share a seed phrase, private key or verification code. A wallet provider generally cannot reverse a confirmed on-chain transaction, and third-party DApps or smart contracts can carry independent risk.