Core principles for Signature Requests

Signature Requests begins with control of credentials and verification of request origin. Around message signatures, transaction signatures and request origin, use three rules: do not disclose sensitive credentials, review every request, and cancel when you cannot verify the details.

Seed phrases and private keys remain under the user’s custody. Official support should never request them or a verification code. Screenshots, cloud sync, chat forwarding and remote-control tools can expand exposure, so prefer offline and independent backups.

Recognize risks involving signature details and contract calls

Risk often arrives through familiar-looking pages, lookalike domains, fake support or urgent prompts. When signature details or contract calls is involved, verify the source again instead of trusting a logo, color scheme or search result.

Wallet connection, message signing, transaction signing and token approval are different actions. A successful connection does not mean later requests should be accepted. Review each target, amount, permission scope and potential on-chain result separately.

What to do when risk assessment looks wrong

If you notice a suspicious request or unexpected record, stop further actions, disconnect unnecessary sessions and check the information related to risk assessment. For unused token permissions, consider revoking them only after confirming the correct network and tool.

If assets have already moved on-chain, verify the transaction hash, destination, network and status through a block explorer. Wallet software generally cannot unilaterally reverse a confirmed blockchain transfer, so be skeptical of guaranteed-recovery claims.

A long-term signature requests checklist

Long-term security covers devices, network environment, credentials, transaction checks and approval management. Keep systems updated, use public computers and public Wi‑Fi cautiously, and re-check pasted addresses before sending.

Security is not a one-time setting. Revisit the risks around message signatures, transaction signatures, request origin, signature details, contract calls and risk assessment; remove access you no longer need; and leave enough time to review important transfers, signatures and approvals.

Connect message signatures, transaction signatures, request origin, signature details, contract calls and risk assessment in one review

After learning the individual concepts in Signature Requests, replay them as one end-to-end decision. Confirm the source and network first; review the account, address or contract context; then inspect fees, signatures or approval details; and finally use the on-chain record to verify what actually happened. This turns separate definitions into a practical review method rather than a vocabulary exercise.

If any step differs from what you expected, stop before confirming and verify again. A page being open, a wallet being connected, or a DApp having been used before does not make a new request automatically trustworthy. For important actions, build familiarity with lower-risk steps first and keep verifiable details such as the network name, public address and transaction hash. Sensitive recovery credentials should never appear in website forms, chat messages or remote-support sessions.

Security principle

imtoken will never ask for your seed phrase, private key or verification code. Review every address, network, signature and approval request independently.