imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken

DApp Approval Security

A focused guide to approval targets, allowances, contract addresses, revocation and recognizing malicious permission requests.

On this pagecheck the target before approvingcheck the allowancecheck the assetreview after usewhat to do when something looks wrong

DApp Approval Security: A focused guide to approval targets, allowances, contract addresses, revocation and recognizing malicious permission requests. Wallet security is built through repeatable habits rather than a single setting. When facing a signature, approval, transfer or recovery request, protecting sensitive information and reviewing details should come before convenience.

Security principle: In DApp Approval Security, imtoken does not ask users to enter a seed phrase, private key or wallet recovery phrase.
Offline backup and private key protection

check the target before approving

Check 1

When working with check the target before approving, place the concept back into a real transaction flow. Information on screen may come from on-chain state, local wallet records or a third-party page, so verify public details such as the network, address, transaction hash or contract before deciding what to do next.

Check 2

In DApp Approval Security, the section on check the target before approving connects directly to the page’s main task. Any page, person or remote-control request that asks for a seed phrase, private key or verification code should be treated as high risk. A safer first response is to stop entering sensitive information and verify the situation using public on-chain data.

Within DApp Approval Security, for check the target before approving, keep the decision reversible for as long as possible: verify information first, then authorize only the minimum action needed. If the request changes the network, transfers an asset, grants spending permission or interacts with a contract, review the exact target and expected result before confirming.

In DApp Approval Security, a good outcome for check the target before approving is not simply that an interface reports success. The useful evidence is whether the expected on-chain state appears on the correct network, under the correct address or contract, and with a transaction or permission record that matches the intended action.

check the allowance

Check 1

A common mistake with check the allowance is drawing a conclusion from a single field. A stronger check compares the active network, destination, asset identity and on-chain record together, especially for same-named tokens, cross-network activity or DApp interactions.

Check 2

In DApp Approval Security, the section on check the allowance connects directly to the page’s main task. Any page, person or remote-control request that asks for a seed phrase, private key or verification code should be treated as high risk. A safer first response is to stop entering sensitive information and verify the situation using public on-chain data.

Within DApp Approval Security, for check the allowance, keep the decision reversible for as long as possible: verify information first, then authorize only the minimum action needed. If the request changes the network, transfers an asset, grants spending permission or interacts with a contract, review the exact target and expected result before confirming.

In DApp Approval Security, a good outcome for check the allowance is not simply that an interface reports success. The useful evidence is whether the expected on-chain state appears on the correct network, under the correct address or contract, and with a transaction or permission record that matches the intended action.

check the asset

Check 1

For check the asset, a useful review pattern is source, scope and result. Source explains where the request came from; scope shows what the action can affect; result is then checked through transaction records, block confirmations or approval state.

Check 2

In DApp Approval Security, the section on check the asset connects directly to the page’s main task. Any page, person or remote-control request that asks for a seed phrase, private key or verification code should be treated as high risk. A safer first response is to stop entering sensitive information and verify the situation using public on-chain data.

Within DApp Approval Security, for check the asset, keep the decision reversible for as long as possible: verify information first, then authorize only the minimum action needed. If the request changes the network, transfers an asset, grants spending permission or interacts with a contract, review the exact target and expected result before confirming.

In DApp Approval Security, a good outcome for check the asset is not simply that an interface reports success. The useful evidence is whether the expected on-chain state appears on the correct network, under the correct address or contract, and with a transaction or permission record that matches the intended action.

review after use

Check 1

review after use is not only a feature label; it also has a specific risk boundary. If a page conflicts with the wallet display or the request cannot be explained clearly, stop before signing, approving or transferring and verify through trusted public information.

Check 2

In DApp Approval Security, the section on review after use connects directly to the page’s main task. Any page, person or remote-control request that asks for a seed phrase, private key or verification code should be treated as high risk. A safer first response is to stop entering sensitive information and verify the situation using public on-chain data.

Within DApp Approval Security, for review after use, keep the decision reversible for as long as possible: verify information first, then authorize only the minimum action needed. If the request changes the network, transfers an asset, grants spending permission or interacts with a contract, review the exact target and expected result before confirming.

In DApp Approval Security, a good outcome for review after use is not simply that an interface reports success. The useful evidence is whether the expected on-chain state appears on the correct network, under the correct address or contract, and with a transaction or permission record that matches the intended action.

what to do when something looks wrong

Check 1

After completing an action involving what to do when something looks wrong, review the outcome again. Transaction status, approval targets, network confirmations and balance changes are stronger evidence than a page-level success message alone.

Check 2

In DApp Approval Security, the section on what to do when something looks wrong connects directly to the page’s main task. Any page, person or remote-control request that asks for a seed phrase, private key or verification code should be treated as high risk. A safer first response is to stop entering sensitive information and verify the situation using public on-chain data.

Within DApp Approval Security, for what to do when something looks wrong, keep the decision reversible for as long as possible: verify information first, then authorize only the minimum action needed. If the request changes the network, transfers an asset, grants spending permission or interacts with a contract, review the exact target and expected result before confirming.

In DApp Approval Security, a good outcome for what to do when something looks wrong is not simply that an interface reports success. The useful evidence is whether the expected on-chain state appears on the correct network, under the correct address or contract, and with a transaction or permission record that matches the intended action.

Important risk reminder

For DApp Approval Security, Remember: the user is responsible for safeguarding the seed phrase and private keys, and official staff will not ask for a seed phrase, private key or verification code. On-chain transactions generally cannot be reversed by a wallet alone, and third-party DApps or smart contracts may involve technical or fraud risks. Review the address, network, amount, approval target and permission scope before acting.

Related reading

Continue with imtoken

Continue from the imtoken download entry after reviewing the key checks in DApp Approval Security.

Download imtoken