Close Menu
  • News
    • Bitcoin
    • Altcoins
    • DeFi
    • Market Cap
  • Blockchain
  • Web 3
    • NFT
    • Metaverse
  • Regulation
  • Analysis
  • Learn
  • Blog
What's Hot

MarsCat joins forces with Memo to drive Web3 data insights and user-friendly experiences

2026-06-24

Bitcoin as a ‘complementary diversifier’? BlackRock says YES, but…

2026-06-24

Bitcoin as a ‘complementary diversifier’? BlackRock says YES, but…

2026-06-24
Facebook X (Twitter) Instagram
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Advertise
Facebook X (Twitter) Instagram
Bitcoin Platform – Bitcoin | Altcoins | Blockchain | News Stories Updated Daily
  • News
    • Bitcoin
    • Altcoins
    • DeFi
    • Market Cap
  • Blockchain

    MarsCat joins forces with Memo to drive Web3 data insights and user-friendly experiences

    2026-06-24

    Manadia joins the Origins Network to advance scalable AI-powered blockchain ecosystems

    2026-06-24

    Chainlink brings Samsung, Toyota and Sony prices on-chain with APAC stock streams

    2026-06-24

    Aztec reaches L2Beat Phase 2 after Governance revokes ownership of the rollup contract

    2026-06-24

    What is MEV? Maximal Extractable Value, the invisible tax on crypto

    2026-06-24
  • Web 3
    • NFT
    • Metaverse
  • Regulation

    Crypto finally has a CLARITY Act date

    2026-06-24

    The US Treasury Department’s $10 billion scam alert shows why crypto is rushing itself into the police force

    2026-06-24

    Stablecoins in Britse ponden gemaximeerd op $53 miljard, terwijl de Bank of England stablecoin-regels vastlegt

    2026-06-22

    De Amerikaanse toekomst van crypto-daders zal worden bepaald door hoe toezichthouders besluiten ze te noemen

    2026-06-22

    De MiCA-deadline zal waarschijnlijk kleinere crypto-apps naar gelicentieerde bewaarrails verplaatsen

    2026-06-22
  • Analysis

    Ethereum Foundation bezuinigt met 20% op personeel, terwijl ETH YTD met 44% daalt ondanks recordgebruik

    2026-06-24

    CZ noemde het no-KYC-model van Hyperliquid “geweldig”

    2026-06-24

    South Korea’s KOSPI crashes 10% as regulator admits ETF error

    2026-06-23

    Trumps quantum computing-push zet 449 miljard dollar aan ‘blootgestelde Bitcoin’ weer in de schijnwerpers

    2026-06-23

    Solana subsidizes large traders before the markets in the chain prove that the activity can continue to exist

    2026-06-23
  • Learn

    Most Profitable Crypto to Mine in 2026: Best Altcoins for Mining

    2026-06-23

    Bitcoin Alternatives: Our Top Altcoin Picks for You in 2026

    2026-06-23

    What Is a Bull Flag Pattern in Crypto and How to Use It

    2026-06-20

    What Is OTC Trading? Over-the-Counter Trading Explained

    2026-06-20

    The Top 10 Bitcoin Wallets in 2026

    2026-06-20
  • Blog
Bitcoin Platform – Bitcoin | Altcoins | Blockchain | News Stories Updated Daily
Home»Analysis»Coinbase security advisory raises alarm about potential phishing risks
Analysis

Coinbase security advisory raises alarm about potential phishing risks

2026-03-19No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Coinbase is directing some Commerce users to a recovery stream ahead of the March 31 migration deadline.

The issue is part of Coinbase’s shutdown plan for older Commerce wallets. In its transition guide, Coinbase says users with funds in a Commerce wallet will need to withdraw them by March 31, 2026, when the Commerce portal and withdrawal tool will become inaccessible.

For users who have backed up their wallets to Google Drive, Coinbase says they should go to the Commerce dashboard, open Settings and Security, reveal the 12-word seed phrase, and use the withdrawal tool at draw.commerce.coinbase.com.

Coinbase says the process is especially important for merchants who have received Bitcoin or other UTXO-based assets, as balances may otherwise be difficult to find in standard wallets.

A seed phrase is the master recovery key for a self-custodial wallet. Coinbase’s own wallet documentation describes it as a 12-word recovery phrase that only the user can access.

Whoever controls this phrase controls access to the wallet and its money. If you lose it, you may lose access to funds. Expose it and the money in the wallet can be emptied.

That’s where the contradiction is hard to miss. Coinbase’s wallet accompaniment tells users never to share a recovery phrase, says the company will never ask for it, and adds a separate warning: “Never post it on a website.”

Still, the Commerce transition guide tells some users to reveal the same phrase as part of an official Coinbase-hosted recovery path.

The company’s explanation is that Commerce wallets are self-custodial and Coinbase does not have access to the phrase or funds, making users responsible for recovery before closure.

See also  This is the next big memecoin for this bull market cycle, according to closely followed crypto analysts

Security researchers see a phishing template

Nevertheless, this requirement from Coinbase has raised alarm bells among many security experts, who criticize the platform for the behavior the page teaches users to accept.

Blockchain security company SlowMist founder Yu Xian said he was surprised that Coinbase would host a page asking users to enter a plaintext reminder for asset recovery, and said the practice was so insecure that he first wondered if the subdomain had been hacked.

The warning sharpened the core criticism of the page: an official brand, an urgent deadline, and a workflow with opening sentences combine to create a format that attackers regularly imitate.

Meanwhile, 23pds, SlowMist’s head of information security, wrote on X that there were “two problems” with the power. First of all, him said:

“Although the link comes from the official Coinbase website, it is extremely foolish to directly ask users to submit their reminder to verify assets.”

Second, he noted that the site had a flawed sitemap that allowed attackers to copy the front end and deploy a near-clone on a similar domain, creating a strong phishing appeal for users who were already ready to trust the Coinbase version.

In addition, blockchain researcher ZachXBT goes further pressed even more direct on that point. In a post on X he wrote:

“So basically Coinbase has an official page that live threat actors can use to target Coinbase users via social engineering if they want?”

Their concerns are not surprising, as phishing and social engineering scams remain one of the most powerful attack vectors against the crypto industry.

See also  XRP price may not see an explosive rally in October as expected, here is why

Last year, ZachXBT revealed that Coinbase users lose more than $300 million annually due to social engineering scams.

CryptoSlate daily briefing

Daily signals, no noise.

Market-moving headlines and context, read in one sitting every morning.

5 minute summary 100,000+ readers

Free. No spam. You can unsubscribe at any time.

Oops, looks like there’s a problem. Please try again.

You are subscribed. Welcome aboard.

This shows why the trade flow has caused such a strong reaction. For years, security teams have taught users that any request containing a seed phrase is the start of a scam.

However, a Coinbase-owned page using the same phrase could change the visual and behavioral cues users should rely on.

Coinbase’s breach history hangs over the debate

Meanwhile, the security debate is heating up as Coinbase is already dealing with the aftereffects of previous social engineering incidents.

In May 2025, Coinbase reported that cybercriminals bribed a group of foreign support agents to steal customer data for social engineering attacks.

The Brian Armstrong-led exchange said the attackers obtained account details from less than 1% of monthly transactions and used it to build lists of customers to contact, pretending to be from the platform.

The company said no private keys had been exposed and promised to refund customers who were tricked into sending money to attackers.

Apart from that, the company also has a previous record of breaches.

Coinbase said this in its 2024 annual report report that third parties obtained login credentials and personal information of at least 6,000 customers in 2021 and used that data to exploit a vulnerability in the account recovery process. The company said it reimbursed affected customers about $25.1 million.

See also  Bitcoin Poised for Positive Performance in Q2 2024: Coinbase Analysts

That history raises the stakes around any official workflow that asks users to process a seed phrase on a live web page.

Security researchers warn that such a branded interface that normalizes seed phrase input will further drive phishing and impersonation attacks, which remain among the most effective attack methods in the industry.

Mentioned in this article

Source link

advisory Alarm Coinbase phishing potential raises risks Security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ethereum Foundation bezuinigt met 20% op personeel, terwijl ETH YTD met 44% daalt ondanks recordgebruik

2026-06-24

Coinbase Pre-IPO Perpetrators Push Crypto Deeper Into the Private World

2026-06-24

CZ noemde het no-KYC-model van Hyperliquid “geweldig”

2026-06-24

South Korea’s KOSPI crashes 10% as regulator admits ETF error

2026-06-23
Add A Comment

Comments are closed.

Top Posts

Bofa CEO teases dollar-pegged stablecoin-is a banking revolution on the horizon?

2025-02-27

Crypto Analyst Says Bitcoin (BTC) Is Poised to Hit New Highs, Warns of Chainlink’s (LINK) ‘Latest Correction’

2023-10-05

Why Investors Aren’t Buying Bitcoin and Ethereum Despite ‘Low’ Prices

2026-02-25
Editors Picks

Dogecoin (DOGE) is building accumulation structure ahead of a potential breakout

2026-02-18

“Trump has positioned himself as the pro-Bitcoin candidate:” Exec

2024-06-25

Bitcoin is bad… but the future looks bright!

2024-01-16

Bitcoin ETFs Consume More BTC Than Miners Produce: What This Shift Means

2024-12-23

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Cryptocurrencies, Defi, NFT, Metaverse and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

MarsCat joins forces with Memo to drive Web3 data insights and user-friendly experiences

Bitcoin as a ‘complementary diversifier’? BlackRock says YES, but…

Bitcoin as a ‘complementary diversifier’? BlackRock says YES, but…

Get Informed

Subscribe to Updates

Get the latest news and Update from Bitcoin Platform about Crypto, Metaverse, NFT and more.

  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Advertise
© 2026 Bitcoinplatform.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.