Coinbase faces backlash over page asking users to enter seed phrases amid phishing concerns

Source Cryptopolitan

A page on an official Coinbase subdomain that prompts users to enter their mnemonic seed phrases in plain text to recover crypto assets has been flagged by blockchain security experts. 

Their main gripe with the Coinbase page setup is that it risks exposing users to textbook social engineering attacks, and that the exposure may already be in the hands of criminals.

The page was published as part of Coinbase Commerce’s wind-down process ahead of a March 31 deadline.

Coinbase draws ire for exposing customers to phishing threats

A Coinbase page was flagged publicly on March 19, 2026, by Yu Xian, known online as Evilcos, the founder of blockchain security firm SlowMist. 

Xian wrote on X while also sharing screenshots, “I’m really puzzled why Coinbase would have a page like this, directly asking users to input their plaintext mnemonic phrases for asset recovery? Such an insecure practice is simply unbelievable… I almost thought the subdomain had been hacked.”

The alarm is also coming at a sensitive period for Coinbase and some of its users, as its Commerce platform is in the final weeks of a shutdown, pushing thousands of merchants to recover funds urgently. 

This is precisely the kind of deadline pressure that makes users hasty and less careful about where they input credentials. 

There is also the option for users to copy the phrases that they saved on cloud storage services like Google Drive.

Coinbase’s own help documentation states that the company will never ask for or have access to a user’s recovery phrase, a principle the Commerce page appears to contradict directly.

How could this be exploited by attackers?

The concern among researchers runs beyond what Coinbase itself might do with the data. The page’s design, they say, provides a blueprint for fraud. 

23pds, Chief Information Security Officer at SlowMist, stated: “While the link is from the official Coinbase website, directly asking users to transmit their mnemonic phrase to verify assets is extremely foolish.”

23pds also added that another issue with the page is that “The website linked to has a flawed sitemap. Attackers could easily use tools like ResourcesSaver to download the front-end code and deploy a similar website. If this is combined with a similar domain like Coinbase for phishing attacks, users could easily fall for the scam.”

On-chain investigator ZachXBT, who has documented hundreds of millions of dollars in crypto theft linked to social engineering, was direct in his assessment. 

“So basically Coinbase has an official page live that threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” he wrote. In a follow-up comment, he added, “Hopefully the team fixes and removes it as soon as possible.”

As of the time of publication, Coinbase had not made any statements addressing the issue or removed the page.

Has Coinbase or its users been exploited before?

Coinbase has been criticized in the past over its handling of social engineering threats targeting its customers. 

In February 2025, ZachXBT reported that users had lost more than $65 million to such attacks in just two months, part of what he estimated to be a $300 million annual drain. The investigator identified patterns in which fraudsters impersonated Coinbase support staff and used cloned admin panels to automate attacks in real time.

A few months later, in May 2025, there was a data breach that exposed the personal data for a subset of users. Coinbase confirmed that the breach happened as a result of criminals bribing overseas support agents. 

The company terminated the staff involved, notified regulators, and offered affected users a year of credit monitoring. It also set aside between $180 million and $400 million to cover remediation costs and voluntary customer reimbursements and announced a $20 million reward for information leading to arrests. 

The current Commerce page may be seen as low-hanging fruit for bad actors right now, and the recent alarm by Evilcos should prompt the exchange to take urgent actions to mitigate any future exploit.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin Drops Below $70,000 as Crypto Rally Fails to MaterializeThe crypto market experienced a significant pullback, Bitcoin (BTCUSD) fell below the key $70,000 mark during intraday trading, triggering short-term stop-loss orders and causing market s
Author  TradingKey
7 hours ago
The crypto market experienced a significant pullback, Bitcoin (BTCUSD) fell below the key $70,000 mark during intraday trading, triggering short-term stop-loss orders and causing market s
placeholder
Gold falls below $4,850 as Fed holds rates steadyGold price (XAU/USD) faces some selling pressure near $4,830 during the early Asian session on Thursday.
Author  FXStreet
15 hours ago
Gold price (XAU/USD) faces some selling pressure near $4,830 during the early Asian session on Thursday.
placeholder
WTI Crude Prices Capped at $100, Has the Rally Ended? How to Trade the Short Term? Today (March 18), WTI crude oil continued to exhibit significant short-term volatility, driven by a tug-of-war between headlines and data. Intraday, prices retreated from Tuesday's high o
Author  TradingKey
Yesterday 10: 33
Today (March 18), WTI crude oil continued to exhibit significant short-term volatility, driven by a tug-of-war between headlines and data. Intraday, prices retreated from Tuesday's high o
placeholder
Silver Price Forecast: XAG/USD consolidates above $79.00; bearish bias intact ahead of FedSilver (XAG/USD) lacks a firm intraday direction and oscillates in a narrow range during the Asian session on Wednesday as traders opt to wait on the sidelines ahead of the crucial FOMC rate decision.
Author  FXStreet
Yesterday 02: 16
Silver (XAG/USD) lacks a firm intraday direction and oscillates in a narrow range during the Asian session on Wednesday as traders opt to wait on the sidelines ahead of the crucial FOMC rate decision.
placeholder
WTI rises above $95.00 as Iran's attacks on facilities fuel supply fearsWest Texas Intermediate (WTI), the US crude oil benchmark, is trading around $95.00 during the early Asian trading hours on Wednesday. The WTI price climbs amid intensifying Middle East conflict and severe supply disruptions.
Author  FXStreet
Yesterday 01: 29
West Texas Intermediate (WTI), the US crude oil benchmark, is trading around $95.00 during the early Asian trading hours on Wednesday. The WTI price climbs amid intensifying Middle East conflict and severe supply disruptions.
goTop
quote