imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.

imtoken · Web3 & DApps

DApp Connections

Before connecting, verify the domain and source. After connecting, verify the requested account and network. Unexpected or poorly explained signatures should be rejected until the user understands why they are needed.

On this pageBefore You BeginStep 1: Confirm Context and IntentStep 2: Perform and Review the ActionStep 3: Check the On-chain ResultCommon MistakesSecurity Checklist

Before You Begin

To understand DApp Connections, start by separating the wallet interface from the underlying chain state. Before connecting, verify the domain and source. After connecting, verify the requested account and network. Unexpected or poorly explained signatures should be rejected until the user understands why they are needed.

Domain checks should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Connection requests should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Account permissions should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. If the origin or meaning of a request cannot be verified, stopping and checking a trusted source is safer than approving something that is not understood.

Step 1: Confirm Context and Intent

In everyday use, connection requests, account permissions and network often appear in the same workflow. They should be evaluated together in the context of the user’s actual intent rather than as isolated interface labels.

Connection requests should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Account permissions should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Network should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. If the origin or meaning of a request cannot be verified, stopping and checking a trusted source is safer than approving something that is not understood.

domain checksDomain checks should be verified in the context of the active network, the user’s intended action and the information shown by the wallet.
connection requestsConnection requests should be verified in the context of the active network, the user’s intended action and the information shown by the wallet.
account permissionsAccount permissions should be verified in the context of the active network, the user’s intended action and the information shown by the wallet.
networkNetwork should be verified in the context of the active network, the user’s intended action and the information shown by the wallet.

Step 2: Perform and Review the Action

A useful review model has three moments: confirm the intended context before acting, inspect the requested permission while signing, and verify the public result after submission. This keeps interface assumptions separate from on-chain facts.

Account permissions should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Network should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Disconnecting stale sessions reduces confusion, although it does not automatically revoke on-chain approvals. If the origin or meaning of a request cannot be verified, stopping and checking a trusted source is safer than approving something that is not understood.

Step 3: Check the On-chain Result

Many problems that appear complicated are really context mismatches: the wrong network, an unexpected contract, a stale permission or a transaction that is still pending. Breaking the problem into those parts makes independent verification easier.

Network should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Disconnecting stale sessions reduces confusion, although it does not automatically revoke on-chain approvals. Domain checks should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. If the origin or meaning of a request cannot be verified, stopping and checking a trusted source is safer than approving something that is not understood.

Common Mistakes

A repeatable routine is more dependable than memory. Confirm the network first, then the destination or contract, then the amount, fee and request details, and finally keep the transaction hash or approval record for later checking.

Disconnecting stale sessions reduces confusion, although it does not automatically revoke on-chain approvals. Domain checks should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Connection requests should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. If the origin or meaning of a request cannot be verified, stopping and checking a trusted source is safer than approving something that is not understood.

  • Confirm the active network
  • Verify the destination or contract
  • Review the amount and fee
  • Understand the signature or approval
  • Keep the transaction hash for verification

Security Checklist

The next step is to connect this topic with transfer checks, wallet security and Web3 permissions. Good technical knowledge should help a user decide what to inspect when a request is unfamiliar, not merely define terminology.

Domain checks should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Connection requests should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. Account permissions should be verified in the context of the active network, the user’s intended action and the information shown by the wallet. If the origin or meaning of a request cannot be verified, stopping and checking a trusted source is safer than approving something that is not understood.