The post Security analysts call out Coinbase for ‘extremely foolish’ phishing exposure appeared on BitcoinEthereumNews.com. A page on an official Coinbase subdomainThe post Security analysts call out Coinbase for ‘extremely foolish’ phishing exposure appeared on BitcoinEthereumNews.com. A page on an official Coinbase subdomain

Security analysts call out Coinbase for ‘extremely foolish’ phishing exposure

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A page on an official Coinbase subdomain that prompts users to enter their mnemonic seed phrases in plain text to recover crypto assets has been flagged by blockchain security experts. 

Their main gripe with the Coinbase page setup is that it risks exposing users to textbook social engineering attacks, and that the exposure may already be in the hands of criminals.

The page was published as part of Coinbase Commerce’s wind-down process ahead of a March 31 deadline.

Coinbase draws ire for exposing customers to phishing threats

A Coinbase page was flagged publicly on March 19, 2026, by Yu Xian, known online as Evilcos, the founder of blockchain security firm SlowMist. 

Xian wrote on X while also sharing screenshots, “I’m really puzzled why Coinbase would have a page like this, directly asking users to input their plaintext mnemonic phrases for asset recovery? Such an insecure practice is simply unbelievable… I almost thought the subdomain had been hacked.”

The alarm is also coming at a sensitive period for Coinbase and some of its users, as its Commerce platform is in the final weeks of a shutdown, pushing thousands of merchants to recover funds urgently. 

This is precisely the kind of deadline pressure that makes users hasty and less careful about where they input credentials. 

There is also the option for users to copy the phrases that they saved on cloud storage services like Google Drive.

Coinbase’s own help documentation states that the company will never ask for or have access to a user’s recovery phrase, a principle the Commerce page appears to contradict directly.

How could this be exploited by attackers?

The concern among researchers runs beyond what Coinbase itself might do with the data. The page’s design, they say, provides a blueprint for fraud. 

23pds, Chief Information Security Officer at SlowMist, stated: “While the link is from the official Coinbase website, directly asking users to transmit their mnemonic phrase to verify assets is extremely foolish.”

23pds also added that another issue with the page is that “The website linked to has a flawed sitemap. Attackers could easily use tools like ResourcesSaver to download the front-end code and deploy a similar website. If this is combined with a similar domain like Coinbase for phishing attacks, users could easily fall for the scam.”

On-chain investigator ZachXBT, who has documented hundreds of millions of dollars in crypto theft linked to social engineering, was direct in his assessment. 

“So basically Coinbase has an official page live that threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” he wrote. In a follow-up comment, he added, “Hopefully the team fixes and removes it as soon as possible.”

As of the time of publication, Coinbase had not made any statements addressing the issue or removed the page.

Has Coinbase or its users been exploited before?

Coinbase has been criticized in the past over its handling of social engineering threats targeting its customers. 

In February 2025, ZachXBT reported that users had lost more than $65 million to such attacks in just two months, part of what he estimated to be a $300 million annual drain. The investigator identified patterns in which fraudsters impersonated Coinbase support staff and used cloned admin panels to automate attacks in real time.

A few months later, in May 2025, there was a data breach that exposed the personal data for a subset of users. Coinbase confirmed that the breach happened as a result of criminals bribing overseas support agents. 

The company terminated the staff involved, notified regulators, and offered affected users a year of credit monitoring. It also set aside between $180 million and $400 million to cover remediation costs and voluntary customer reimbursements and announced a $20 million reward for information leading to arrests. 

The current Commerce page may be seen as low-hanging fruit for bad actors right now, and the recent alarm by Evilcos should prompt the exchange to take urgent actions to mitigate any future exploit.

Source: https://www.cryptopolitan.com/security-analysts-coinbase-phishing-exposure/

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.03684
$0.03684$0.03684
+1.57%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Tips to Optimise Particle Size Distribution in Milling

Tips to Optimise Particle Size Distribution in Milling

The Significance of Particle Size in Milling Processes In milling processes, achieving the right particle size is very important. It affects product quality, performance
Share
Techbullion2026/03/20 01:06
Senate Republicans Hold Closed-Door Meeting on Cryptocurrency Yield Regulation

Senate Republicans Hold Closed-Door Meeting on Cryptocurrency Yield Regulation

Senate Republicans held a closed-door meeting to discuss cryptocurrency yield regulation, signaling a critical and sensitive phase in broader digital asset legislation
Share
coinlineup2026/03/20 01:30
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32