imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken

Signature Requests

A signature can represent login, a message proof or transaction authorization, so a generic “Sign” prompt is never enough context.

Verify the networkReview the requestKeep verifiable records
Check 1

Signature types

Signature types is a practical part of understanding Signature Requests. A signature can represent login, a message proof or transaction authorization, so a generic “Sign” prompt is never enough context. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

The risky part of Signature types within Signature Requests is often the surrounding context rather than the button itself: which network is active, which site initiated the request, what permission is being granted, and whether the amount and fee make sense. Turning those checks into a routine is more reliable than reacting to prompts one by one.

For Signature types, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with signature types
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone
Check 2

Message signatures

Message signatures is a practical part of understanding Signature Requests. A signature can represent login, a message proof or transaction authorization, so a generic “Sign” prompt is never enough context. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

imtoken guidance focuses on information you can verify. When something is unclear, do not rely on a single line in a pop-up. Check the address, network, contract, transaction history and explorer data where relevant, then decide whether the action matches your intent.

For Message signatures, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with message signatures
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone
Check 3

Transaction signatures

Transaction signatures is a practical part of understanding Signature Requests. A signature can represent login, a message proof or transaction authorization, so a generic “Sign” prompt is never enough context. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

Transaction signatures within Signature Requests is not an isolated feature. In practice it is shaped by network state, account permissions, transaction parameters and user decisions. Understanding those relationships first makes similar-looking screens and labels much less confusing.

For Transaction signatures, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with transaction signatures
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone
Check 4

Reject & verify

Reject & verify is a practical part of understanding Signature Requests. A signature can represent login, a message proof or transaction authorization, so a generic “Sign” prompt is never enough context. Before acting, confirm that the active account, target network and intended outcome all match, then review the parameters shown in the request.

A useful way to think about Reject & verify within Signature Requests is to separate what the interface displays from what the blockchain records. The wallet organizes information and submits requests, while the target network records the resulting state. Addresses, networks, contracts and transaction hashes are therefore important verification points.

For Reject & verify, a repeatable sequence is useful: verify the source and network, check the address or contract, review the amount, permission or fee, and keep a transaction hash when one is created. This does not remove every risk, but it makes decisions easier to explain and problems easier to trace.

Practical checks

  • Verify the network and account before working with reject & verify
  • Double-check important addresses, contracts, amounts or permissions
  • Never send a seed phrase, private key or verification code to anyone

Security statement

Seed phrases and private keys remain under the user’s control. Official personnel will not ask for them or for verification codes; on-chain transactions generally cannot be reversed by a wallet alone; third-party DApps and smart contracts may carry risk.

imtoken

Ready to get started?

The download entry always goes through the dedicated download page. Keep verifying networks, addresses and request details before acting.

Download imtoken