Articles
Crypto Market Analysis

Coinbase Commerce page requests seed phrases, raising security concerns

User Image

От Анонимный

Создано March 19, 2026|2 мин. чтения
Main Image

A Coinbase subdomain linked to its Commerce tool reportedly directed users to a withdrawal page asking to enter their seed phrases, raising concerns among security observers.

Security researchers have raised concerns about a Coinbase-associated Commerce page that appeared to prompt users to enter wallet recovery phrases, warning that such a flow could normalize behavior commonly exploited in phishing scams.

The page has circulated widely on social media after being flagged by the founder of the blockchain security platform SlowMist, Yu Xian, widely known as Cos.

“I’m really puzzled why Coinbase would have a page like this, directly asking users to input their plaintext mnemonic phrases for asset recovery,” Yu wrote in an X post on Wednesday, adding: “Such an insecure practice is simply unbelievable.”

Coinbase has yet to address the issue publicly. The company told Cointelegraph it was looking into the matter and did not provide additional information. Cointelegraph also approached Yu Xian for comment, but had not received a response by publication.

Recovery phrases give full control over a self-custody wallet and should never be shared with third parties, customer support agents or untrusted websites. They are normally used only in trusted wallet recovery or import flows.

According to blockchain sleuth ZachXBT, the page in question was referenced in a Coinbase Help guide related to its Commerce product.

The guide, now appearing to have been removed, reportedly outlined an option for users to recover funds by importing their seed phrase into a compatible wallet such as Coinbase Wallet or MetaMask. It also directed users to a withdrawal tool hosted at the same subdomain that has drawn scrutiny.

The help documentation also emphasizes that Commerce wallets are self-custodial, meaning Coinbase does not have access to users’ seed phrases and cannot recover funds if they are lost.

Related: OpenClaw devs targeted by phishing scam promising free ‘CLAW’ tokens

“So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” ZachXBT wrote on X.

It remains unclear whether the page in question was the result of a technical error or another issue on Coinbase’s side.

In another guide, Coinbase strongly advised users to never paste seed phrases into any website.

On Tuesday, Coinbase warned that scammers are posing as customer support over the phone or online to steal login information and verification codes. The company said it will never reach out, directing users to its official channels on X and Reddit.

Magazine: Bitcoin’s ‘narrative vacuum,’ Ethereum now inevitable: Trade Secrets

Source: CoinTelegraph


Другие статьи, опубликованные недавно

ZetaChain dismissed bug report that could have prevented $334K exploit
ZetaChain dismissed bug report that could have prevented $334K exploit

Crypto Market Analysis

The vulnerability behind ZetaChain's $334,000 exploit had been reported through its bug bounty progr...

XRP set for ‘strongest’ 2026 monthly ETF inflows as bulls target $2
XRP set for ‘strongest’ 2026 monthly ETF inflows as bulls target $2

Crypto Market Analysis

XRP price technicals are favoring a potential rebound to $2.15 as long as support at $1.40 is held, ...

Andre Cronje says DeFi is ‘no longer DeFi’ as builders debate circuit breakers
Andre Cronje says DeFi is ‘no longer DeFi’ as builders debate circuit breakers

DeFi

Flying Tulip’s Andre Cronje says circuit breakers can give teams time to respond during abnormal o...

Monthly prediction market volume hits $25.7B as user activity shifts beyond one-off events
Monthly prediction market volume hits $25.7B as user activity shifts beyond one-off events

Crypto Market Analysis

A new report by Bitget Wallet and Polymarket found that retail users are driving repeat activity on ...

MoonPay buys crypto security firm Sodot in $100M push into institutional crypto
MoonPay buys crypto security firm Sodot in $100M push into institutional crypto

Crypto Market Analysis

MoonPay has acquired Israel-based crypto security infrastructure provider Sodot, forming the foundat...

Dogecoin leads pre-FOMC rally with 12% gains: Is DOGE price headed to $0.33?
Dogecoin leads pre-FOMC rally with 12% gains: Is DOGE price headed to $0.33?

Meme Coins

Dogecoin’s latest rebound resembled bounces witnessed in mid-2023, raising the odds of a rally tow...