imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Security Guide

Phishing & Scam Awareness

Phishing & Scam Awareness connects lookalike domains, fake support, fake airdrops, and malicious signatures into a practical workflow for understanding, acting, verifying on-chain results, and reviewing security.

Illustration about offline private key protection
Core principleYour seed phrase and private key stay under your control. Official personnel will not ask you to send them.
On this page
  1. Core protection principles for lookalike domains
  2. Recognize risks involving fake support and fake airdrops
  3. What to check before accepting malicious signatures
  4. What to do when clipboard attacks looks suspicious
  5. A long-term checklist for remote-control scams

Core protection principles for lookalike domains

To decide whether Phishing & Scam Awareness worked as expected, do not rely on an interface message alone; understand how lookalike domains, fake support, and fake airdrops relate. lookalike domains describes one important object in this topic, while fake support and fake airdrops help define the environment and the state you need to observe. Familiar labels are not enough: the same token name, address format, or feature entry can lead to different results across networks and contract contexts.

Impersonation sites often use lookalike domains, search ads, fake support, or supposed airdrops to create urgency. Review the domain, source, wallet request, and resulting permissions together rather than judging a page only by how closely it resembles an official site. Keep malicious signatures, clipboard attacks, and remote-control scams in the same context. Start from the task, then separate information that can be public from credentials or permissions that can change on-chain state. This prevents “I can see it” from becoming “I approved it,” and prevents “I submitted it” from being mistaken for “it is confirmed.”

Recognize risks involving fake support and fake airdrops

A useful starting point for Phishing & Scam Awareness is to ask what fake support, fake airdrops, and malicious signatures each mean in the workflow. A reliable sequence is to verify fake support, check fake airdrops, and then read the specific fields related to malicious signatures. When clipboard attacks is involved, determine whether the action only displays information, creates a connection, requests a signature, or actually submits an on-chain transaction. Those outcomes are not interchangeable.

If the task also involves remote-control scams or lookalike domains, map the destination address, network, allowance, fee, or contract target to the action before submitting. Afterwards, verify the result through a transaction hash, block explorer, permission record, or wallet history. With Phishing & Scam Awareness, being able to explain each step is more reliable than simply seeing a success message.

What to check before accepting malicious signatures

Before using Phishing & Scam Awareness, separate the roles of fake airdrops, malicious signatures, and clipboard attacks; that is more durable than memorizing interface positions. Prefer information that can be independently checked on-chain. fake airdrops, malicious signatures, and clipboard attacks often describe the object, environment, and state, while remote-control scams and lookalike domains can explain fees, confirmation progress, or permissions. Interface caches, node delay, and congestion can temporarily make the displayed state differ from the network state.

Do not immediately resend or approve again. Confirm the network first, then check whether a record related to fake support already exists. If you have a transaction hash, continue the investigation around that record. Repeating an action can add fees, change nonce ordering, or create extra permissions that make the original issue harder to diagnose.

What to do when clipboard attacks looks suspicious

With Phishing & Scam Awareness, malicious signatures, clipboard attacks, and remote-control scams often appear together, but they answer different questions. Common mistakes include trusting a name without checking malicious signatures, trusting an icon without verifying clipboard attacks, or assuming that seeing remote-control scams makes later requests acceptable. When lookalike domains and fake support appear, distinguish a connection, signature, approval, transfer, and contract call by what each one can actually change.

Third-party DApps, smart contracts, bridges, and service interfaces can introduce technical or operational risk. A normal imtoken workflow does not ask you to enter a seed phrase, private key, recovery phrase, or verification code into a website. For on-chain permissions, verify the spender, scope, and purpose; for transfers, verify the address, network, and amount. If fake airdrops does not match what you expected, stop new requests, keep the transaction or permission evidence, and review the network, address, contract, and request source before continuing.

A long-term checklist for remote-control scams

Place Phishing & Scam Awareness inside a real wallet workflow and review clipboard attacks, remote-control scams, and lookalike domains independently. Turn the workflow into three phases: before submission, verify clipboard attacks and remote-control scams; during submission, read lookalike domains and fake support; afterwards, confirm the outcome through fake airdrops and malicious signatures. The same routine remains useful when you change devices, networks, or DApps.

For Phishing & Scam Awareness, the durable evidence is not where a button appears. It is whether the address is correct, the network matches, the signature can be explained, the spender and allowance make sense, and the transaction has an on-chain record. If one step cannot be explained, stop and re-check the source and purpose.

  • Confirm lookalike domains matches the task
  • Cross-check fake support and fake airdrops
  • Read fields related to malicious signatures before submitting
  • Verify the outcome through clipboard attacks or an on-chain record
  • Review and maintain remote-control scams when it is no longer needed
  • Never send a seed phrase, private key, or verification code to anyone