imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken Knowledge Center

Signature Requests

A practical imtoken guide to signature requests, including core concepts, verification steps and risk-aware usage.

On this page
  1. Core concepts
  2. Checks before you act
  3. How to evaluate a live request
  4. Risks and boundaries
  5. How to verify the outcome

Core concepts

To understand Signature Requests, treat message signatures and transaction signatures as parts of the same on-chain workflow. The interface is only the entry point; the selected network, current chain state and permission scope determine what actually happens. Confirm the destination, source and network before continuing so the meaning of the request stays clear.

For message signatures, first define its role in the current task, then check whether transaction signatures and readable details are consistent. When unknown requests is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For rejecting and reviewing, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: message signatures
  • Cross-check: transaction signatures and readable details
  • Review carefully: unknown requests
  • Verify afterward: rejecting and reviewing

Checks before you act

transaction signatures rarely appears in isolation. It often intersects with readable details and unknown requests. A useful pattern is to separate each action into four checks: identify the object, verify the network, review permissions, and confirm the result. If one of those checks cannot be completed, stop and verify rather than relying on an unfamiliar site or remote instructions.

For transaction signatures, first define its role in the current task, then check whether readable details and unknown requests are consistent. When rejecting and reviewing is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For message signatures, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: transaction signatures
  • Cross-check: readable details and unknown requests
  • Review carefully: rejecting and reviewing
  • Verify afterward: message signatures

How to evaluate a live request

When using imtoken for Signature Requests, prioritize information that can be independently verified, such as addresses, network names, contract addresses, transaction hashes and block-explorer records. Visual design, urgency messages or claims from an unknown support account are not substitutes for verifiable on-chain details.

For readable details, first define its role in the current task, then check whether unknown requests and rejecting and reviewing are consistent. When message signatures is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For transaction signatures, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: readable details
  • Cross-check: unknown requests and rejecting and reviewing
  • Review carefully: message signatures
  • Verify afterward: transaction signatures

Risks and boundaries

From a risk perspective, message signatures and transaction signatures deserve an independent review. Once a transaction is confirmed on-chain, a wallet normally cannot reverse it unilaterally. DApps and smart contracts can also introduce permission and contract risks, so every signature, approval and transfer should be understood before it is accepted.

For unknown requests, first define its role in the current task, then check whether rejecting and reviewing and message signatures are consistent. When transaction signatures is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For readable details, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: unknown requests
  • Cross-check: rejecting and reviewing and message signatures
  • Review carefully: transaction signatures
  • Verify afterward: readable details

How to verify the outcome

After a Signature Requests task is completed, review readable details and unknown requests to make sure the outcome matches the intent. Long-lived approvals and persistent connections should be revisited periodically. Good wallet hygiene is a repeated process of checking critical details and retaining traceable on-chain information, not a one-time setting.

For rejecting and reviewing, first define its role in the current task, then check whether message signatures and transaction signatures are consistent. When readable details is involved, do not rely only on a default option; understand which account, asset or permission it may affect. For unknown requests, use on-chain records and the actual status as the source of truth. imtoken will not ask users to enter a seed phrase, private key or wallet recovery phrase on a web page, and it will not require remote control of a device for sensitive wallet actions.

  • Confirm: rejecting and reviewing
  • Cross-check: message signatures and transaction signatures
  • Review carefully: readable details
  • Verify afterward: unknown requests

Practical checklist

  • Never share your seed phrase, private key or verification code.
  • Verify the address, network and amount before sending.
  • Review each DApp signature and token approval independently.
  • Use transaction hashes and block explorers to verify on-chain status.
  • Revoke approvals and disconnect sessions that are no longer needed.