ZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns.  A live page onZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns.  A live page on

Coinbase Page Flags Security Risk Over Seed Phrase Entry

2026/03/20 01:00
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

ZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns. 

A live page on Coinbase’s official domain is drawing security alarm from researchers. The page, hosted at withdraw.commerce.coinbase.com, asks users to enter a 12-word seed phrase as part of an asset recovery process tied to Coinbase Commerce. The exchange has not pulled the page down.

On-chain investigator ZachXBT raised the alarm on X, questioning whether Coinbase had thought through what a page like this could enable. “So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” ZachXBT wrote. The post drew thousands of interactions almost immediately.

When an Official Page Becomes the Weapon

Security researcher evilcos flagged the same page earlier on X, saying the practice of asking users to input plaintext mnemonic phrases was simply hard to believe from a major exchange. The researcher said the subdomain initially looked like it had been compromised. It had not. The page is official.

The Coinbase Commerce help documentation, visible on the recovery page, explains the process. It tells merchants their funds may be spread across hundreds or even thousands of wallet addresses because Commerce generated a new address for every payment received. Importing the seed phrase into a standard wallet, it says, may not show the full balance. Standard wallets typically scan only the first 20 unused addresses. For Bitcoin and other UTXO-based assets, Coinbase directed users toward the withdrawal tool before March 31, 2026.

The documentation also instructs users on how to retrieve a seed phrase backed up to Google Drive, then enter it at the withdrawal tool. This is where researchers say the risk sits.

Two Separate Problems, One Very Dangerous Page

Security researcher im23pds posted on X breaking the concern into two distinct issues. First, even though the link originates from an official Coinbase domain, asking users to transmit their mnemonic phrase to verify assets is careless by any security standard. Second, the website has a flawed sitemap. Attackers could use tools like ResourcesSaver to download the front-end code entirely and deploy a near-identical copy. Pair that with a lookalike domain, and a Coinbase phishing campaign becomes significantly easier to run.

In a separate earlier post, im23pds noted on X that the page was built carelessly. The team launched it without even setting up a sitemap. That kind of oversight makes the page even more accessible to anyone wanting to copy its structure.

Source:  im23pds 

The core danger is straightforward. Threat actors do not need to break into Coinbase systems. They point a user at a fake version of an already-existing official page that asks for a seed phrase. The user, conditioned by the real page, hands it over.

The Broader Pattern Here

This is not a new pattern for the exchange. ZachXBT has previously documented how bad actors exploit Coinbase’s brand in social engineering campaigns, using impersonation and fake support channels to drain wallets. The Commerce recovery page, in this case, does the groundwork for scammers without anyone having to impersonate a thing.

The page remains live. Coinbase has not responded publicly to the concerns raised.

The post Coinbase Page Flags Security Risk Over Seed Phrase Entry appeared first on Live Bitcoin News.

Market Opportunity
Particl Logo
Particl Price(PART)
$0.1504
$0.1504$0.1504
-0.26%
USD
Particl (PART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
World Gold Council’s Pivotal Framework Promises Unprecedented Market Trust

World Gold Council’s Pivotal Framework Promises Unprecedented Market Trust

The post World Gold Council’s Pivotal Framework Promises Unprecedented Market Trust appeared on BitcoinEthereumNews.com. Tokenized Gold Revolution: World Gold Council
Share
BitcoinEthereumNews2026/03/20 03:58
BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

The post BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus appeared on BitcoinEthereumNews.com. Press Releases are sponsored content and not a part of Finbold’s editorial content. For a full disclaimer, please . Crypto assets/products can be highly risky. Never invest unless you’re prepared to lose all the money you invest. Curacao, Curacao, September 17th, 2025, Chainwire BetFury steps onto the stage of SBC Summit Lisbon 2025 — one of the key gatherings in the iGaming calendar. From 16 to 18 September, the platform showcases its brand strength, deepens affiliate connections, and outlines its plans for global expansion. BetFury continues to play a role in the evolving crypto and iGaming partnership landscape. BetFury’s Participation at SBC Summit The SBC Summit gathers over 25,000 delegates, including 6,000+ affiliates — the largest concentration of affiliate professionals in iGaming. For BetFury, this isn’t just visibility, it’s a strategic chance to present its Affiliate Program to the right audience. Face-to-face meetings, dedicated networking zones, and affiliate-focused sessions make Lisbon the ideal ground to build new partnerships and strengthen existing ones. BetFury Meets Affiliate Leaders at its Massive Stand BetFury arrives at the summit with a massive stand placed right in the center of the Affiliate zone. Designed as a true meeting hub, the stand combines large LED screens, a sleek interior, and the best coffee at the event — but its core mission goes far beyond style. Here, BetFury’s team welcomes partners and affiliates to discuss tailored collaborations, explore growth opportunities across multiple GEOs, and expand its global Affiliate Program. To make the experience even more engaging, the stand also hosts: Affiliate Lottery — a branded drum filled with exclusive offers and personalized deals for affiliates. Merch Kits — premium giveaways to boost brand recognition and leave visitors with a lasting conference memory. Besides, at SBC Summit Lisbon, attendees have a chance to meet the BetFury team along…
Share
BitcoinEthereumNews2025/09/18 01:20