What's Hot

    US Fed, Treasury assess spillover risks from $1.8 trillion private credit

    04/11/2026

    Ethereum Mirrors A 2023 Setup As Buyers Take Control Of Derivatives On Binance

    04/11/2026

    Robert Pape: 75% chance of US-Iran conflict escalation, the complexities of targeting nuclear materials, and the resilience of Iran’s regime

    04/11/2026
    Facebook Twitter Instagram
    • Business
    • Markets
    • Get In Touch
    • Our Authors
    Facebook Twitter Instagram
    Cryptomarketnews
    • Home
    • Business

      Exodus Rolls Out ‘Exodus Pay’ to Turn Bitcoin Wallet Into Spending App

      04/10/2026

      Suspect Arrested After Molotov Cocktail Thrown at Sam Altman’s San Francisco Home

      04/10/2026

      Elon Musk’s SpaceX Is Nearing Its $1.75 Trillion IPO—Bitget Is Offering Pre-IPO Exposure

      04/10/2026

      Zcash Could Rise to $420 After 62% Weekly Price Spike, Traders Predict

      04/10/2026

      Trump-Linked WLFI Erases $427 Million From Market Cap on DeFi Loan, Token Unlock Proposal

      04/10/2026
    • Technology
      1. Business
      2. Insights
      3. View All

      Exodus Rolls Out ‘Exodus Pay’ to Turn Bitcoin Wallet Into Spending App

      04/10/2026

      Suspect Arrested After Molotov Cocktail Thrown at Sam Altman’s San Francisco Home

      04/10/2026

      Elon Musk’s SpaceX Is Nearing Its $1.75 Trillion IPO—Bitget Is Offering Pre-IPO Exposure

      04/10/2026

      Zcash Could Rise to $420 After 62% Weekly Price Spike, Traders Predict

      04/10/2026

      WLFI Crashes 13% To All-Time Lows Amid Growing Liquidation Fears For World Liberty Financial

      04/10/2026

      Early WLFI investors face shrinking profits as $1.28 billion supply shock looms

      04/10/2026

      BlackRock Posts Massive Bitcoin ETF Inflows As Morgan Stanley Debuts MSBT With Strong Early Demand

      04/10/2026

      How This Popular Trader Went From $100 Million To Less Than $1,000

      04/10/2026

      This ‘Space Invaders’ Clone Game Pays Real Bitcoin—If You’re Skilled, Lucky or Rich

      04/10/2026

      BitTensor AI Token Plunges as Top Builder Departs Over Decentralization Doubts

      04/10/2026

      The CIA Let AI Write Its First Intelligence Report—And AI ‘Coworkers’ Are Up Next

      04/10/2026

      Gen Z Thinks AI Is Rotting Their Brains, But Can’t Stop Using It: Survey

      04/10/2026
    • Insights
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      Chaos Labs Leaves Aave Due to Budget, Risk Disagreements

      04/07/2026

      Polymarket To Replace USDC.e With USDC-Backed Token In Exchange Upgrade

      04/07/2026

      US Senator Hagerty Confirms April Timeline for Crypto Market Structure

      04/06/2026

      Trump’s Iran Deadline and the Case for a $75K Bitcoin Price Rally

      04/06/2026

      BlackRock Posts Massive Bitcoin ETF Inflows As Morgan Stanley Debuts MSBT With Strong Early Demand

      04/10/2026

      Japan Moves To Classify Bitcoin And Crypto As Financial Instruments Under New Bill

      04/10/2026

      Strategy’s (MSTR) Bitcoin Ambition Is Reshaping Corporate Finance. Everyone Else Is Falling Behind

      04/09/2026

      Solo Bitcoin Miner Defies 1-in-100,000 Odds To Win $222K Block Reward

      04/09/2026

      WLFI Crashes 13% To All-Time Lows Amid Growing Liquidation Fears For World Liberty Financial

      04/10/2026

      How This Popular Trader Went From $100 Million To Less Than $1,000

      04/10/2026

      Solana Gains Tokenized Stock Push As Traders Watch $1,000 Talk

      04/10/2026

      Why A Bitcoin Price Breakdown To $50,000 Could Be Important For Long-Term Bullishness

      04/10/2026

      Bittensor’s TAO plunges 27% after top AI builder exit

      04/10/2026

      US inflation soars to 3.3% in largest jump since 2021

      04/10/2026

      CLARITY Act faces White House blitz as Treasury and SEC flood Senate with coordinated pressure this week

      04/10/2026

      How Trump-linked WLFI set up a lending model where lenders will pay the price of failure

      04/10/2026

      WLFI Crashes 13% To All-Time Lows Amid Growing Liquidation Fears For World Liberty Financial

      04/10/2026

      Early WLFI investors face shrinking profits as $1.28 billion supply shock looms

      04/10/2026

      BlackRock Posts Massive Bitcoin ETF Inflows As Morgan Stanley Debuts MSBT With Strong Early Demand

      04/10/2026

      How This Popular Trader Went From $100 Million To Less Than $1,000

      04/10/2026
    • Markets
    • Get In Touch
    Cryptomarketnews
    Home»Insights»Videos»Coinbase security advice sparks alarm over potential phishing risk
    Videos

    Coinbase security advice sparks alarm over potential phishing risk

    adminBy admin03/19/2026No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Coinbase is directing some Commerce users to a seed-phrase recovery flow ahead of a March 31 migration deadline.

    The issue sits inside Coinbase’s shutdown plan for legacy Commerce wallets. In its transition guide, Coinbase says users with funds in a Commerce wallet must withdraw them before March 31, 2026, when the Commerce portal and withdrawal tool will become inaccessible.

    For users who backed up their wallet to Google Drive, Coinbase says they should go to the Commerce dashboard, open Settings and Security, reveal the 12-word seed phrase, and use the withdrawal tool at withdraw.commerce.coinbase.com.

    Coinbase says the process is especially important for merchants that received Bitcoin or other UTXO-based assets because balances may otherwise be hard to surface in standard wallets.

    A seed phrase is the master recovery key for a self-custody wallet. Coinbase’s own wallet documentation describes it as a 12-word recovery phrase that only the user has access to.

    Whoever controls that phrase controls access to the wallet and its funds. Lose it, and access to funds can be lost. Expose it, and funds in the wallet can be drained.

    That is where the contradiction becomes hard to miss. Coinbase’s wallet guidance tells users never to share a recovery phrase, says the firm will never ask for it, and adds a separate warning: “Never paste it into any website.”

    Yet the Commerce transition guide tells some users to reveal the same phrase as part of an official Coinbase-hosted recovery path.

    The company’s explanation is that Commerce wallets are self-custodial, and Coinbase does not have access to the phrase or the funds, which leaves users responsible for recovery before the shutdown.

    Security researchers see a phishing template

    Nonetheless, this Coinbase demand has rung the alarm bells for many security experts, who are criticizing the platform for the behavior its page teaches users to accept.

    Blockchain security firm SlowMist founder Yu Xian said he was puzzled that Coinbase would host a page asking users to enter a mnemonic phrase in plain text for asset recovery and said the practice was so insecure that he first wondered whether the subdomain had been hacked.

    The warning sharpened the core criticism around the page: an official brand, an urgent deadline, and a seed-phrase workflow combine into a format attackers regularly mimic.

    Meanwhile, SlowMist chief information security officer 23pds wrote on X that there were “two issues” with the flow. First, he said:

    “While the link is from the official Coinbase website, directly asking users to transmit their mnemonic phrase to verify assets is extremely foolish.”

    Secondly, he noted that the site had a flawed sitemap that could let attackers copy the front end and deploy a near-clone on a lookalike domain, creating a strong phishing lure for users already primed to trust the Coinbase version.

    Additionally, blockchain investigator ZachXBT further pressed on that point even more directly. In a post on X, he wrote:

    “So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?”

    Their concerns are unsurprising, considering phishing and social engineering scams remain one of the most potent attack vectors against the crypto industry.

    Last year, ZachXBT revealed that Coinbase users lose more than $300 million annually due to social engineering scams.

    CryptoSlate Daily Brief

    Daily signals, zero noise.

    Market-moving headlines and context delivered every morning in one tight read.

    5-minute digest 100k+ readers

    Free. No spam. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re subscribed. Welcome aboard.

    This captures why the Commerce flow has triggered such a strong reaction. Security teams have spent years teaching users that any request involving a seed phrase is the start of a scam.

    However, a Coinbase-owned page handling the same phrase could change the visual and behavioral cues users have been taught to rely on.

    Coinbase’s breach history hangs over the debate

    Meanwhile, the security debate lands harder because Coinbase is already dealing with the aftereffects of past social-engineering incidents.

    In May 2025, Coinbase reported that cybercriminals bribed a group of overseas support agents to steal customer data for social-engineering attacks.

    The Brian Armstrong-led exchange said the attackers obtained account data for fewer than 1% of monthly transacting users and used it to compile lists of customers they could contact, pretending to be from the platform.

    The company said no private keys were exposed and pledged to reimburse customers who were tricked into sending funds to attackers.

    Apart from that, the company also has an earlier breach record.

    Coinbase said in its 2024 annual report that in 2021, third parties obtained login credentials and personal information for at least 6,000 customers and used those details to exploit a vulnerability in the account recovery process. The firm said it reimbursed impacted customers about $25.1 million.

    That history raises the stakes around any official workflow that asks users to handle a seed phrase on a live web page.

    Security researchers warn that such a branded interface that normalizes seed-phrase entry will further boost phishing and impersonation attacks, which remain among the industry’s most effective attack methods.

    Mentioned in this article



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    WLFI Crashes 13% To All-Time Lows Amid Growing Liquidation Fears For World Liberty Financial

    04/10/2026

    Early WLFI investors face shrinking profits as $1.28 billion supply shock looms

    04/10/2026

    BlackRock Posts Massive Bitcoin ETF Inflows As Morgan Stanley Debuts MSBT With Strong Early Demand

    04/10/2026

    How This Popular Trader Went From $100 Million To Less Than $1,000

    04/10/2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    01/20/2021

    Jack Dorsey Says Bitcoin Will Unite The World

    01/15/2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    01/15/2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    US Fed, Treasury assess spillover risks from $1.8 trillion private credit

    04/11/2026

    Ethereum Mirrors A 2023 Setup As Buyers Take Control Of Derivatives On Binance

    04/11/2026

    Robert Pape: 75% chance of US-Iran conflict escalation, the complexities of targeting nuclear materials, and the resilience of Iran’s regime

    04/11/2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    • Home
    • Business
    • Markets
    • Technology
    • Contact us
    © 2026 CryptoDailyNews.net

    Type above and press Enter to search. Press Esc to cancel.