imtoken Knowledge Center
Seed Phrases & Private Keys
Seed phrases and private keys are core access credentials and should be self-custodied, never shared through chats, screenshots or exposed cloud storage.
Protect secret credentials
Security starts by separating public information from secret credentials. An address can be shared for receiving assets; a seed phrase or private key should never be shared. In the context of Seed Phrases & Private Keys, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
Recognize high-risk situations
Attackers often use urgency, imitation pages, fake support and deceptive approvals to make users skip verification. Slow down and check the domain and request details. In the context of Seed Phrases & Private Keys, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
Device and network environment
Public computers, remote-control software, clipboard manipulation and untrusted networks widen the attack surface. High-value actions should be performed in a controlled device environment. In the context of Seed Phrases & Private Keys, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
Final checks for transfers, signatures and approvals
Security starts by separating public information from secret credentials. An address can be shared for receiving assets; a seed phrase or private key should never be shared. In the context of Seed Phrases & Private Keys, the practical goal is to understand what the wallet is showing, what the network is recording, and which details must be verified before you approve an action.
A useful check is to separate interface information from on-chain facts. Review the active network, address, transaction hash, contract or permission scope as relevant, and avoid assuming that a familiar symbol or screen guarantees the intended result.
- Verify the active network and destination before confirming.
- Treat seed phrases and private keys as secret credentials.
- Review DApp, signature and approval requests independently.
