imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
Security

Approval Security

Review approval targets, scope, allowance and duration.

On this page

Understand DApp approvals and allowance

Review approval targets, scope, allowance and duration. The purpose of this Approval Security guide is not to memorize an interface. It is to understand what DApp approvals, allowance, and approved spender each tell you, and how those signals fit together during an on-chain action.

When using imtoken for this topic, begin with the network and the origin of the request. Dapp approvals gives one part of the picture, allowance defines an important boundary, and approved spender helps explain whether the result matches what you intended.

A durable workflow is to start with information you can verify: identify the asset, spender, and allowance for every approval, review permissions that remain active, and consider revoking those no longer needed. This keeps the decision grounded even when an app layout, DApp interface, or network condition changes.

It is also useful to separate what a wallet interface displays from what the blockchain records. A wallet can organize requests and show status, while network rules, contract execution, and block inclusion determine the on-chain result. This is also an important part of keeping the Approval Security workflow clear and reviewable.

Practical checklist

  • Confirm the network and purpose of the Approval Security action.
  • Distinguish DApp approvals, allowance, and approved spender.
  • Prefer verifiable fields over names or icons.
  • Define the expected result before acting and verify it afterward.

Put approved spender into a real workflow

For Approval Security, think in four stages: prepare, review, act, and verify. During preparation, define the goal and relevant DApp approvals; during review, check allowance and approved spender; act only on a request you understand; then use revocation or another on-chain record to verify the outcome.

If a prompt contains an address, network, contract, fee, signature, or approval, do not collapse those fields into one generic “confirm” step. Reading them separately makes unexpected network switches, changed recipients, or broader permissions easier to spot. This is also an important part of keeping the Approval Security workflow clear and reviewable.

When the network needs time to process a request, a temporarily unchanged interface is not proof of failure and is not a reason to submit the same action again immediately. Check approved spender, transaction history, or an appropriate block explorer first.

A fixed review order is more reliable than memory. Repeating the same checks for Approval Security creates a traceable workflow and makes troubleshooting easier because you can return to the last step that has a verifiable result.

Practical checklist

  • Check DApp approvals during preparation.
  • Review allowance and approved spender before approval.
  • Approve only a request you understand.
  • Use revocation to verify the outcome.

Recognize risks around long-lived permission

A high allowance may remain active long after a session is forgotten, extending exposure to the approved contract. The broader lesson is that a familiar page does not prove a request is correct; review the network, address, contract, signature content, or permission scope that actually defines the action.

Names alone are weak evidence. Dapp approvals, allowance, or long-lived permission may look familiar across networks and applications while representing different underlying objects. For important actions, prefer complete addresses, contracts, and transaction identifiers.

If the observed state differs from your expectation, avoid repeated confirmations or broadcasts while the situation is unclear. Record the active network and public transaction information, then determine whether the issue is pending network state, display behavior, permission scope, or the request itself. This is also an important part of keeping the Approval Security workflow clear and reviewable.

The security boundary remains consistent: never send a seed phrase, private key, or verification code to anyone, and never enter those secrets into an ordinary webpage. imtoken staff will not ask for them, while third-party DApps and contracts require independent review. This is also an important part of keeping the Approval Security workflow clear and reviewable.

Practical checklist

  • Risk to remember: A high allowance may remain active long after a session is forgotten, extending exposure to the approved contract.
  • Do not skip network, address, or contract checks because a page looks familiar.
  • Stop adding new actions if the state is unclear.
  • Never provide a seed phrase, private key, or verification code.

Use revocation to close the loop

After the action, use a short Approval Security checklist and review approved contract, token, allowance, original context, ongoing need, and revocation transaction state. Together these fields answer four practical questions: where the action occurred, who or what it targeted, what authority or value moved, and what the network recorded.

Verification is not a promise of absolute safety. Its value is that avoidable mistakes can be detected before the next action. In particular, make sure revocation is consistent with the active network, account, and intended outcome. This is also an important part of keeping the Approval Security workflow clear and reviewable.

Over time, include long-lived permission in periodic reviews rather than waiting for a problem. Remove connections or permissions that no longer serve a purpose, keep useful public transaction records, and maintain clear boundaries between accounts, networks, and DApps.

The goal of learning Approval Security is to make decisions that remain understandable when interfaces change or networks are busy. Establish the facts first, approve only what you understand, and use on-chain information to verify what happened.

Practical checklist

  • Review: approved contract, token, allowance, original context, ongoing need, and revocation transaction state.
  • Confirm the result matches the active network and intended target.
  • Consider removing connections or permissions you no longer need.
  • Evaluate third-party DApps and smart contracts independently.
Security principle

Keep seed phrases and private keys under your own control. imtoken staff will never ask for them. Verify address, network and request details before a transfer, signature or approval. On-chain transactions generally cannot be reversed unilaterally by a wallet.

imtoken

Move from knowledge to careful action

Verify the network, address and request before confirming.

Download imtoken