Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

March 20, 2026

From Seed Phrases to Passkeys: The Evolution of Crypto UX

March 20, 2026

Coinbase security advice sparks alarm over potential phishing risk

March 20, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    $72,500 Rejection and Support Levels to Watch

    March 20, 2026

    Analyst Who Nailed 2025 Bitcoin Top Says BTC Mirroring 2022 Bottom Pattern – Here’s His Timeline

    March 20, 2026

    OpenClaw GitHub phishing scam uses fake $5,000 token airdrops gain wallet access

    March 19, 2026

    Bitcoin Price Falls Below $70,000 On Oil Spike, Fed Hold

    March 19, 2026

    Whales and Charts Say the Same Thing

    March 18, 2026

    Ethereum Price Nears Breakout Zone—Will Confirmation Push ETH to $3,000?

    March 18, 2026

    The 8-Year Ethereum Convergence That Says An Altcoin Season Stronger Than 2021 Is Coming

    March 18, 2026

    $33M ETH Withdrawn From Exchanges In Hours

    March 18, 2026

    Bitcoin To Rally 250% This Year? Crypto Founder’s Bullish Prediction Shows New ATHs

    March 20, 2026

    Signal That Led To Last 2 Altcoin Seasons Has Returned, And Here’s How Bitcoin Fits In

    March 19, 2026

    Bitcoin Risks Drop To $52,000, Veteran Analyst Aksel Kibar Says

    March 19, 2026

    Analyst Maps Path Back To All-Time High

    March 19, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    US Ranks #1 in CoinGecko Global Meme Coin Interest Report

    December 18, 2025

    Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

    March 20, 2026

    From Seed Phrases to Passkeys: The Evolution of Crypto UX

    March 20, 2026

    Coinbase security advice sparks alarm over potential phishing risk

    March 20, 2026

    Bitcoin To Rally 250% This Year? Crypto Founder’s Bullish Prediction Shows New ATHs

    March 20, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

    March 20, 2026

    Fomoin Taps Ads3 to Accelerate the Development of Web3 Projects

    March 20, 2026

    Moody’s brings credit ratings onchain with Canton Network integration

    March 19, 2026

    4AI Collaborates with PlutonAI to Drive DeFAI Innovation in Web3 via AI Agents

    March 19, 2026

    Crypto Scam “ShieldGuard” Dismantled After Malware Discovery

    March 18, 2026

    Leaked Database Sheds Light on Iranian Crypto Sanctions Evasion

    March 4, 2026

    DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

    March 3, 2026

    Aeternum Botnet Shifts Command Control to Polygon Blockchain

    February 27, 2026

    Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

    March 20, 2026

    From Seed Phrases to Passkeys: The Evolution of Crypto UX

    March 20, 2026

    Coinbase security advice sparks alarm over potential phishing risk

    March 20, 2026

    Bitcoin To Rally 250% This Year? Crypto Founder’s Bullish Prediction Shows New ATHs

    March 20, 2026
  • Web 3
    1. Gaming
    2. View All

    From Seed Phrases to Passkeys: The Evolution of Crypto UX

    March 20, 2026

    Pudgy Penguins Launched A New Game. Crypto Scammers Made A Fake Version

    March 19, 2026

    Dan Houser: “Goodfellas” revolutionized cinema and storytelling

    March 19, 2026

    GCOIN Debuts as Playnance Accelerates Ecosystem Growth

    March 18, 2026

    Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

    March 20, 2026

    From Seed Phrases to Passkeys: The Evolution of Crypto UX

    March 20, 2026

    Coinbase security advice sparks alarm over potential phishing risk

    March 20, 2026

    Bitcoin To Rally 250% This Year? Crypto Founder’s Bullish Prediction Shows New ATHs

    March 20, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Positive Development for the Clarity Act, the Cryptocurrency Law Everyone in the US Has Been Waiting For! One of the Most Authoritative Figures Announced…

    March 20, 2026

    Bitcoin Depot Flags Control ‘Weaknesses’ as Connecticut Halts Its Operations

    March 20, 2026

    Stablecoins just lost key battle as insurance protection to be reserved only for bank-issued tokens

    March 19, 2026

    Coin Center urges SEC to prioritize rulemaking over no-action letters

    March 19, 2026

    Is Mastercard embracing crypto or trying to contain it?

    March 13, 2026

    AI is boosting demand for high skill tech jobs while quietly killing entry-level roles

    March 7, 2026

    XRP and XRPL get a credibility lift from Ripple’s expanding footprint

    March 5, 2026

    XRP rewrites the playbook for altcoin ETF approvals to surge in late 2026 after a wave of futures listings

    March 4, 2026

    Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

    March 20, 2026

    From Seed Phrases to Passkeys: The Evolution of Crypto UX

    March 20, 2026

    Coinbase security advice sparks alarm over potential phishing risk

    March 20, 2026

    Bitcoin To Rally 250% This Year? Crypto Founder’s Bullish Prediction Shows New ATHs

    March 20, 2026
  • Analysis

    Crypto just opened S&P 500 trading for the weekend while Wall Street shuts down

    March 19, 2026

    While Bitcoin Hits $70K, River Coin, Dexe, and Quant Move In Opposite Directions.

    March 19, 2026

    Hyperliquid beats Cardano’s ADA to enter crypto top 10 assets

    March 19, 2026

    Institutional Inflows Into Bitcoin and Crypto ETFs Soar to $1,060,000,000 in One Week: CoinShares

    March 19, 2026

    Ethereum gains ground over Bitcoin amid rising US-Iran war

    March 19, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    What Is Farcaster? The Decentralized Social Media Protocol

    February 10, 2026

    What Is Venice AI? The Privacy-Focused Chatbot

    January 13, 2026

    Coinbase security advice sparks alarm over potential phishing risk

    March 20, 2026

    Coinbase’s $70B Bitcoin move made it look like investors were selling — but no one actually did

    March 16, 2026

    Why Binance suddenly isn’t afraid of negative press anymore

    March 14, 2026

    Crypto platform aims to let retail investors buy IPO shares at the same price as Wall Street insiders

    March 6, 2026

    Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

    March 20, 2026

    From Seed Phrases to Passkeys: The Evolution of Crypto UX

    March 20, 2026

    Coinbase security advice sparks alarm over potential phishing risk

    March 20, 2026

    Bitcoin To Rally 250% This Year? Crypto Founder’s Bullish Prediction Shows New ATHs

    March 20, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Wallets and Exchanges»Coinbase security advice sparks alarm over potential phishing risk
Wallets and Exchanges

Coinbase security advice sparks alarm over potential phishing risk

March 20, 2026No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Coinbase is directing some Commerce users to a seed-phrase recovery flow ahead of a March 31 migration deadline.

The issue sits inside Coinbase’s shutdown plan for legacy Commerce wallets. In its transition guide, Coinbase says users with funds in a Commerce wallet must withdraw them before March 31, 2026, when the Commerce portal and withdrawal tool will become inaccessible.

For users who backed up their wallet to Google Drive, Coinbase says they should go to the Commerce dashboard, open Settings and Security, reveal the 12-word seed phrase, and use the withdrawal tool at withdraw.commerce.coinbase.com.

Coinbase says the process is especially important for merchants that received Bitcoin or other UTXO-based assets because balances may otherwise be hard to surface in standard wallets.

A seed phrase is the master recovery key for a self-custody wallet. Coinbase’s own wallet documentation describes it as a 12-word recovery phrase that only the user has access to.

Whoever controls that phrase controls access to the wallet and its funds. Lose it, and access to funds can be lost. Expose it, and funds in the wallet can be drained.

That is where the contradiction becomes hard to miss. Coinbase’s wallet guidance tells users never to share a recovery phrase, says the firm will never ask for it, and adds a separate warning: “Never paste it into any website.”

Yet the Commerce transition guide tells some users to reveal the same phrase as part of an official Coinbase-hosted recovery path.

The company’s explanation is that Commerce wallets are self-custodial, and Coinbase does not have access to the phrase or the funds, which leaves users responsible for recovery before the shutdown.

See also  Coinbase CEO leverages Davos 2026 to speak to world leaders on crypto adoption

Security researchers see a phishing template

Nonetheless, this Coinbase demand has rung the alarm bells for many security experts, who are criticizing the platform for the behavior its page teaches users to accept.

Blockchain security firm SlowMist founder Yu Xian said he was puzzled that Coinbase would host a page asking users to enter a mnemonic phrase in plain text for asset recovery and said the practice was so insecure that he first wondered whether the subdomain had been hacked.

The warning sharpened the core criticism around the page: an official brand, an urgent deadline, and a seed-phrase workflow combine into a format attackers regularly mimic.

Meanwhile, SlowMist chief information security officer 23pds wrote on X that there were “two issues” with the flow. First, he said:

“While the link is from the official Coinbase website, directly asking users to transmit their mnemonic phrase to verify assets is extremely foolish.”

Secondly, he noted that the site had a flawed sitemap that could let attackers copy the front end and deploy a near-clone on a lookalike domain, creating a strong phishing lure for users already primed to trust the Coinbase version.

Additionally, blockchain investigator ZachXBT further pressed on that point even more directly. In a post on X, he wrote:

“So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?”

Their concerns are unsurprising, considering phishing and social engineering scams remain one of the most potent attack vectors against the crypto industry.

Last year, ZachXBT revealed that Coinbase users lose more than $300 million annually due to social engineering scams.

CryptoSlate Daily Brief

See also  Coinbase CEO denies White House clash, says negotiations are ongoing

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

This captures why the Commerce flow has triggered such a strong reaction. Security teams have spent years teaching users that any request involving a seed phrase is the start of a scam.

However, a Coinbase-owned page handling the same phrase could change the visual and behavioral cues users have been taught to rely on.

Coinbase’s breach history hangs over the debate

Meanwhile, the security debate lands harder because Coinbase is already dealing with the aftereffects of past social-engineering incidents.

In May 2025, Coinbase reported that cybercriminals bribed a group of overseas support agents to steal customer data for social-engineering attacks.

The Brian Armstrong-led exchange said the attackers obtained account data for fewer than 1% of monthly transacting users and used it to compile lists of customers they could contact, pretending to be from the platform.

The company said no private keys were exposed and pledged to reimburse customers who were tricked into sending funds to attackers.

Apart from that, the company also has an earlier breach record.

Coinbase said in its 2024 annual report that in 2021, third parties obtained login credentials and personal information for at least 6,000 customers and used those details to exploit a vulnerability in the account recovery process. The firm said it reimbursed impacted customers about $25.1 million.

That history raises the stakes around any official workflow that asks users to handle a seed phrase on a live web page.

See also  Gemini stock could sink if yield ambitions die under harsh SEC settlement terms

Security researchers warn that such a branded interface that normalizes seed-phrase entry will further boost phishing and impersonation attacks, which remain among the industry’s most effective attack methods.

Mentioned in this article
Advice Alarm Coinbase phishing Potential Risk Security sparks
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

OpenClaw GitHub phishing scam uses fake $5,000 token airdrops gain wallet access

March 19, 2026

TermiX.AI Collaborates With GoPlus Security To Advance AI Security Systems To Drive Seamless, Safe Web3 Applications

March 17, 2026

Texas Firm Handing Out up to $5,000 per Person After Data Breach Exposed Names, Social Security Numbers and More

March 17, 2026

Congress has only weeks left to convince banks on crypto CLARITY Act or risk losing it to midterms

March 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

GrowHub Signs ESG Blockchain Agreement With Republic of Srpska

September 13, 2025

Neurolov and Qitmeer Partner to Drive Decentralized AI Compute and Web3 Payments

September 9, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Dow Protocol and Conflux Network Partner to Revolutionize Working Capital with Blockchain Payment Rails

March 20, 2026

From Seed Phrases to Passkeys: The Evolution of Crypto UX

March 20, 2026

Coinbase security advice sparks alarm over potential phishing risk

March 20, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.