imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken · Knowledge and practical checks

DApp Connections

A DApp connection opens an account interaction channel; it does not make every later request trustworthy. Keep checking the domain and request details.

Verify the DApp entry point

Before connecting, inspect the full domain and how you reached it. Search ads, direct messages, and shortened links can lead to look-alike pages, so a familiar logo is not enough.

For a service you use regularly, save a verified entry point instead of rediscovering it through search each time.

Understand what a basic connection reveals

A connection commonly lets a page see a public address, current chain, and connection state. Those are not private keys, but a public address may reveal on-chain activity, so connect only where it serves a real purpose.

Choose the intended account rather than accepting whichever account the browser remembers.

Network switching is not asset bridging

A DApp may request another chain because its contracts live there. Confirm the chain name and purpose before switching.

Changing the selected network does not automatically move tokens from the previous network.

Review what comes after connection

A successful connection may be followed by a login signature, token approval, or transaction. These are separate actions with separate effects.

Repeated prompts that do not fit the stated task are a reason to stop and re-check the domain.

Disconnect when the session is no longer useful

End sessions you no longer need to reduce clutter and accidental interaction. If you granted token permissions, inspect those separately because disconnecting does not normally modify on-chain allowances.

A clean connection list makes unfamiliar sessions easier to notice.

A session does not prove a site is safe

Connection status is only a technical relationship between the page and wallet.

First-time DApp connection checklist

Treat the first connection as a limited session. Pick the right account and network and allow only the actions needed for the feature you intend to use.

Keep account choice intentional

A page that asks for a seed phrase, private key, recovery phrase, or verification code before connecting is not following a normal wallet-connection flow.

Once connected, verify that the site recognizes the expected account and chain before moving to any signature or transaction.

  • Use a verified domain
  • Select the intended account and network
  • Reject unrelated follow-up requests
  • Disconnect unused sessions and review approvals