imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

Security Focus

Seed Phrase & Private Keys

A private key directly controls an account, while a seed phrase can often derive multiple account keys; both are highly sensitive. This page explains Seed Phrase & Private Keys through practical checks, network context and security decisions rather than feature labels alone.

On this page
01

what seed phrases and private keys represent

A private key directly controls an account, while a seed phrase can often derive multiple account keys; both are highly sensitive. This matters in practice because blockchain outcomes are determined by the selected network and the request that is signed, not merely by what a button is called. For what seed phrases and private keys represent, prioritize information you can verify: the active network, public address, contract target and transaction status. Turning those details into a repeatable checklist is more reliable than reacting to vague interface messages.

Offline backups reduce network exposure but also need protection from loss, fire, water and unauthorized photography. It also helps to separate three layers: what the wallet displays, what the network has actually recorded, and what a third-party service claims. When something looks wrong, identify the layer first and then verify with a transaction hash, block explorer or explicit network parameters. No legitimate what seed phrases and private keys represent workflow requires a seed phrase, private key or verification code to be sent to another person.

02

basic offline backup methods

Offline backups reduce network exposure but also need protection from loss, fire, water and unauthorized photography. It also helps to separate three layers: what the wallet displays, what the network has actually recorded, and what a third-party service claims. When something looks wrong, identify the layer first and then verify with a transaction hash, block explorer or explicit network parameters. No legitimate basic offline backup methods workflow requires a seed phrase, private key or verification code to be sent to another person.

If key exposure is suspected, move controllable assets to a newly secured wallet and review approvals associated with the affected accounts. If the action includes a signature, approval or contract call, inspect the permission scope and possible asset impact separately. Friendly labels are not a substitute for the underlying request. Check the target, asset, amount or allowance, network and final confirmation details before proceeding. This sequence reduces mistakes caused by urgency, phishing or the wrong network.

  • Verify the network, address and public on-chain information relevant to basic offline backup methods.
  • Never send a seed phrase, private key or verification code to anyone.
  • For DApps or contracts, review each signature and approval scope separately.
03

screenshot and cloud-storage risks

If key exposure is suspected, move controllable assets to a newly secured wallet and review approvals associated with the affected accounts. If the action includes a signature, approval or contract call, inspect the permission scope and possible asset impact separately. Friendly labels are not a substitute for the underlying request. Check the target, asset, amount or allowance, network and final confirmation details before proceeding. This sequence reduces mistakes caused by urgency, phishing or the wrong network.

A private key directly controls an account, while a seed phrase can often derive multiple account keys; both are highly sensitive. This matters in practice because blockchain outcomes are determined by the selected network and the request that is signed, not merely by what a button is called. For screenshot and cloud-storage risks, prioritize information you can verify: the active network, public address, contract target and transaction status. Turning those details into a repeatable checklist is more reliable than reacting to vague interface messages.

04

what to do after suspected exposure

A private key directly controls an account, while a seed phrase can often derive multiple account keys; both are highly sensitive. This matters in practice because blockchain outcomes are determined by the selected network and the request that is signed, not merely by what a button is called. For what to do after suspected exposure, prioritize information you can verify: the active network, public address, contract target and transaction status. Turning those details into a repeatable checklist is more reliable than reacting to vague interface messages.

Offline backups reduce network exposure but also need protection from loss, fire, water and unauthorized photography. It also helps to separate three layers: what the wallet displays, what the network has actually recorded, and what a third-party service claims. When something looks wrong, identify the layer first and then verify with a transaction hash, block explorer or explicit network parameters. No legitimate what to do after suspected exposure workflow requires a seed phrase, private key or verification code to be sent to another person.

  • Verify the network, address and public on-chain information relevant to what to do after suspected exposure.
  • Never send a seed phrase, private key or verification code to anyone.
  • For DApps or contracts, review each signature and approval scope separately.