ZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns.  A live page onZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns.  A live page on

Coinbase Page Flags Security Risk Over Seed Phrase Entry

2026/03/20 01:00
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

ZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns. 

A live page on Coinbase’s official domain is drawing security alarm from researchers. The page, hosted at withdraw.commerce.coinbase.com, asks users to enter a 12-word seed phrase as part of an asset recovery process tied to Coinbase Commerce. The exchange has not pulled the page down.

On-chain investigator ZachXBT raised the alarm on X, questioning whether Coinbase had thought through what a page like this could enable. “So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” ZachXBT wrote. The post drew thousands of interactions almost immediately.

When an Official Page Becomes the Weapon

Security researcher evilcos flagged the same page earlier on X, saying the practice of asking users to input plaintext mnemonic phrases was simply hard to believe from a major exchange. The researcher said the subdomain initially looked like it had been compromised. It had not. The page is official.

The Coinbase Commerce help documentation, visible on the recovery page, explains the process. It tells merchants their funds may be spread across hundreds or even thousands of wallet addresses because Commerce generated a new address for every payment received. Importing the seed phrase into a standard wallet, it says, may not show the full balance. Standard wallets typically scan only the first 20 unused addresses. For Bitcoin and other UTXO-based assets, Coinbase directed users toward the withdrawal tool before March 31, 2026.

The documentation also instructs users on how to retrieve a seed phrase backed up to Google Drive, then enter it at the withdrawal tool. This is where researchers say the risk sits.

Two Separate Problems, One Very Dangerous Page

Security researcher im23pds posted on X breaking the concern into two distinct issues. First, even though the link originates from an official Coinbase domain, asking users to transmit their mnemonic phrase to verify assets is careless by any security standard. Second, the website has a flawed sitemap. Attackers could use tools like ResourcesSaver to download the front-end code entirely and deploy a near-identical copy. Pair that with a lookalike domain, and a Coinbase phishing campaign becomes significantly easier to run.

In a separate earlier post, im23pds noted on X that the page was built carelessly. The team launched it without even setting up a sitemap. That kind of oversight makes the page even more accessible to anyone wanting to copy its structure.

Source:  im23pds 

The core danger is straightforward. Threat actors do not need to break into Coinbase systems. They point a user at a fake version of an already-existing official page that asks for a seed phrase. The user, conditioned by the real page, hands it over.

The Broader Pattern Here

This is not a new pattern for the exchange. ZachXBT has previously documented how bad actors exploit Coinbase’s brand in social engineering campaigns, using impersonation and fake support channels to drain wallets. The Commerce recovery page, in this case, does the groundwork for scammers without anyone having to impersonate a thing.

The page remains live. Coinbase has not responded publicly to the concerns raised.

The post Coinbase Page Flags Security Risk Over Seed Phrase Entry appeared first on Live Bitcoin News.

Market Opportunity
Particl Logo
Particl Price(PART)
$0,1528
$0,1528$0,1528
-0,19%
USD
Particl (PART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

EUR/CHF slides as Euro struggles post-inflation data

EUR/CHF slides as Euro struggles post-inflation data

The post EUR/CHF slides as Euro struggles post-inflation data appeared on BitcoinEthereumNews.com. EUR/CHF weakens for a second straight session as the euro struggles to recover post-Eurozone inflation data. Eurozone core inflation steady at 2.3%, headline CPI eases to 2.0% in August. SNB maintains a flexible policy outlook ahead of its September 25 decision, with no immediate need for easing. The Euro (EUR) trades under pressure against the Swiss Franc (CHF) on Wednesday, with EUR/CHF extending losses for the second straight session as the common currency struggles to gain traction following Eurozone inflation data. At the time of writing, the cross is trading around 0.9320 during the American session. The latest inflation data from Eurostat showed that Eurozone price growth remained broadly stable in August, reinforcing the European Central Bank’s (ECB) cautious stance on monetary policy. The Core Harmonized Index of Consumer Prices (HICP), which excludes volatile items such as food and energy, rose 2.3% YoY, in line with both forecasts and the previous month’s reading. On a monthly basis, core inflation increased by 0.3%, unchanged from July, highlighting persistent underlying price pressures in the bloc. Meanwhile, headline inflation eased to 2.0% YoY in August, down from 2.1% in July and slightly below expectations. On a monthly basis, prices rose just 0.1%, missing forecasts for a 0.2% increase and decelerating from July’s 0.2% rise. The inflation release follows last week’s ECB policy decision, where the central bank kept all three key interest rates unchanged and signaled that policy is likely at its terminal level. While officials acknowledged progress in bringing inflation down, they reiterated a cautious, data-dependent approach going forward, emphasizing the need to maintain restrictive conditions for an extended period to ensure price stability. On the Swiss side, disinflation appears to be deepening. The Producer and Import Price Index dropped 0.6% in August, marking a sharp 1.8% annual decline. Broader inflation remains…
Share
BitcoinEthereumNews2025/09/18 03:08
Interview | HIVE CFO: Hydro-cooled mining and AI cloud give us an edge post-halving

Interview | HIVE CFO: Hydro-cooled mining and AI cloud give us an edge post-halving

As Bitcoin mining enters a new chapter post-halving, HIVE Digital Technologies is taking a measured, ambitious approach to growth. In this interview, Darcy Daubaras, CFO of HIVE, offers an inside look at how the company plans to scale its hashrate…
Share
Crypto.news2025/06/19 01:52
Vistra (VST) Stock Drops 7% as Insider Sales Spook the Market

Vistra (VST) Stock Drops 7% as Insider Sales Spook the Market

TLDR Vistra (VST) stock fell as much as 7.16% as investors reacted to heavy insider selling by the CEO and top executives filed with the SEC. The stock also hit
Share
Coincentral2026/03/21 01:25