imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Seed Phrase & Private Keys

Learn why seed phrases and private keys must remain under user control and why exposure is irreversible.

On this pageSeed phrase and key relationshipWho should hold themOffline backup principlesCommon exposure pathsWhat to do after exposure

Seed phrase and key relationship

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For seed phrase and key relationship, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

A practical check

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For seed phrase and key relationship, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

Before proceeding, confirm the network, the address or contract, the amount or permission scope, and the expected result. Keep sensitive recovery information offline and never send a seed phrase, private key, or verification code to another person.

Who should hold them

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For who should hold them, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

A practical check

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For who should hold them, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

Before proceeding, confirm the network, the address or contract, the amount or permission scope, and the expected result. Keep sensitive recovery information offline and never send a seed phrase, private key, or verification code to another person.

Offline backup principles

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For offline backup principles, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

A practical check

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For offline backup principles, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

Before proceeding, confirm the network, the address or contract, the amount or permission scope, and the expected result. Keep sensitive recovery information offline and never send a seed phrase, private key, or verification code to another person.

Common exposure paths

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For common exposure paths, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

A practical check

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For common exposure paths, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

Before proceeding, confirm the network, the address or contract, the amount or permission scope, and the expected result. Keep sensitive recovery information offline and never send a seed phrase, private key, or verification code to another person.

What to do after exposure

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For what to do after exposure, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

A practical check

Security is a repeatable process rather than a single feature. Seed phrases and private keys should remain under the user’s control, and official personnel should never ask for them. Any website, chat, or remote-support request that asks you to send a recovery phrase, private key, or verification code should be treated as high risk. For what to do after exposure, separate the object you are acting on, the active network, the expected outcome, and the evidence you can independently verify. Do not rely on interface wording alone; use addresses, transaction hashes, explorers, and contract details where appropriate. For this topic, a useful sequence is: understand the concept, check before acting, submit only when the details are clear, verify on-chain status, and review any permissions that remain afterward.

Before proceeding, confirm the network, the address or contract, the amount or permission scope, and the expected result. Keep sensitive recovery information offline and never send a seed phrase, private key, or verification code to another person.
On-chain transactions generally cannot be unilaterally reversed by a wallet. Third-party DApps, smart contracts, bridges, and staking services may involve technical or operational risk. Digital-asset prices can also fluctuate. Review each action based on your own circumstances.

Keep learning with imtoken

Use the related guides to understand the network, permissions, and security checks before your next on-chain action.

Download imtoken