imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken

Approval Security

Review DApp approval targets, permission scope, malicious signatures and stale approvals.

On this page

Understand Approval target first

In Approval Security, identifying who initiated a request, which network is involved and what will change matters more than moving quickly. Approval target tells you what is being reviewed now, while Permission scope and Malicious signatures provide context for whether the next action makes sense. Before proceeding, confirm that the wallet and network are the ones you intended to use, then review the address, contract or request origin. If the purpose is unclear or the network does not match, stop rather than guessing.

A reliable Approval Security workflow keeps verifiable references such as the network name, address or contract address, transaction hash, block-explorer status and the exact permission being requested. Asset names and icons are useful hints but are not a substitute for on-chain identifiers. With Approval target, avoid confirming something simply because it looks familiar; spoofed pages, wrong networks and malicious requests are designed to exploit that shortcut.

After an action involving Approval target, review the result. If a transaction was created, use its hash to check broadcast, block inclusion and confirmations. If a DApp session or approval was created, identify the connected origin and permission scope, and consider disconnecting or revoking access when it is no longer needed. This turns a one-time action into a process you can verify later.

What to review in practice

  • Confirm the active network is the one you intended and understand how Approval target relates to the action.
  • Verify addresses, contracts and request origins rather than trusting names or icons alone.
  • Before submission, review amount, gas, approval scope or signature details; afterward, keep verifiable on-chain references.

How Permission scope changes the workflow

To understand Permission scope, place it back inside the full Approval Security workflow. Permission scope tells you what is being reviewed now, while Malicious signatures and Contract checks provide context for whether the next action makes sense. Before proceeding, confirm that the wallet and network are the ones you intended to use, then review the address, contract or request origin. If the purpose is unclear or the network does not match, stop rather than guessing.

A reliable Approval Security workflow keeps verifiable references such as the network name, address or contract address, transaction hash, block-explorer status and the exact permission being requested. Asset names and icons are useful hints but are not a substitute for on-chain identifiers. With Permission scope, avoid confirming something simply because it looks familiar; spoofed pages, wrong networks and malicious requests are designed to exploit that shortcut.

After an action involving Permission scope, review the result. If a transaction was created, use its hash to check broadcast, block inclusion and confirmations. If a DApp session or approval was created, identify the connected origin and permission scope, and consider disconnecting or revoking access when it is no longer needed. This turns a one-time action into a process you can verify later.

What to review in practice

  • Confirm the active network is the one you intended and understand how Approval target relates to the action.
  • Verify addresses, contracts and request origins rather than trusting names or icons alone.
  • Before submission, review amount, gas, approval scope or signature details; afterward, keep verifiable on-chain references.

Build a review sequence around Malicious signatures

To understand Malicious signatures, place it back inside the full Approval Security workflow. Malicious signatures tells you what is being reviewed now, while Contract checks and Revocation provide context for whether the next action makes sense. Before proceeding, confirm that the wallet and network are the ones you intended to use, then review the address, contract or request origin. If the purpose is unclear or the network does not match, stop rather than guessing.

A reliable Approval Security workflow keeps verifiable references such as the network name, address or contract address, transaction hash, block-explorer status and the exact permission being requested. Asset names and icons are useful hints but are not a substitute for on-chain identifiers. With Malicious signatures, avoid confirming something simply because it looks familiar; spoofed pages, wrong networks and malicious requests are designed to exploit that shortcut.

After an action involving Malicious signatures, review the result. If a transaction was created, use its hash to check broadcast, block inclusion and confirmations. If a DApp session or approval was created, identify the connected origin and permission scope, and consider disconnecting or revoking access when it is no longer needed. This turns a one-time action into a process you can verify later.

What to review in practice

  • Confirm the active network is the one you intended and understand how Approval target relates to the action.
  • Verify addresses, contracts and request origins rather than trusting names or icons alone.
  • Before submission, review amount, gas, approval scope or signature details; afterward, keep verifiable on-chain references.

Risks and common mistakes involving Contract checks

To understand Contract checks, place it back inside the full Approval Security workflow. Contract checks tells you what is being reviewed now, while Revocation and Approval target provide context for whether the next action makes sense. Before proceeding, confirm that the wallet and network are the ones you intended to use, then review the address, contract or request origin. If the purpose is unclear or the network does not match, stop rather than guessing.

A reliable Approval Security workflow keeps verifiable references such as the network name, address or contract address, transaction hash, block-explorer status and the exact permission being requested. Asset names and icons are useful hints but are not a substitute for on-chain identifiers. With Contract checks, avoid confirming something simply because it looks familiar; spoofed pages, wrong networks and malicious requests are designed to exploit that shortcut.

After an action involving Contract checks, review the result. If a transaction was created, use its hash to check broadcast, block inclusion and confirmations. If a DApp session or approval was created, identify the connected origin and permission scope, and consider disconnecting or revoking access when it is no longer needed. This turns a one-time action into a process you can verify later.

What to review in practice

  • Confirm the active network is the one you intended and understand how Approval target relates to the action.
  • Verify addresses, contracts and request origins rather than trusting names or icons alone.
  • Before submission, review amount, gas, approval scope or signature details; afterward, keep verifiable on-chain references.

Turn Revocation into a repeatable habit

To understand Revocation, place it back inside the full Approval Security workflow. Revocation tells you what is being reviewed now, while Approval target and Permission scope provide context for whether the next action makes sense. Before proceeding, confirm that the wallet and network are the ones you intended to use, then review the address, contract or request origin. If the purpose is unclear or the network does not match, stop rather than guessing.

A reliable Approval Security workflow keeps verifiable references such as the network name, address or contract address, transaction hash, block-explorer status and the exact permission being requested. Asset names and icons are useful hints but are not a substitute for on-chain identifiers. With Revocation, avoid confirming something simply because it looks familiar; spoofed pages, wrong networks and malicious requests are designed to exploit that shortcut.

After an action involving Revocation, review the result. If a transaction was created, use its hash to check broadcast, block inclusion and confirmations. If a DApp session or approval was created, identify the connected origin and permission scope, and consider disconnecting or revoking access when it is no longer needed. This turns a one-time action into a process you can verify later.

What to review in practice

  • Confirm the active network is the one you intended and understand how Approval target relates to the action.
  • Verify addresses, contracts and request origins rather than trusting names or icons alone.
  • Before submission, review amount, gas, approval scope or signature details; afterward, keep verifiable on-chain references.
Security principle: Users remain responsible for their seed phrases and private keys. imtoken will never ask for a seed phrase, private key or verification code. Third-party DApps and smart contracts can carry risk, so review each signature and approval separately.

Related reading

Ready to use imtoken?

All download actions go through the dedicated download page.

Download imtoken