Close Menu
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
    • Mining
  • Stocks
  • Forex
  • Personal Finance
  • World Economy
  • AI in Finance
  • Commodities
  • DeFi
  • Fintech
  • NFTs
  • Learn Finance
Trending
  • $105 Breakout Or Double-Pair Collapse Ahead?
  • Six weeks until Devcon SEA in Bangkok
  • Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed
  • Why The XRP Supply In The Billions Is Not A Problem
  • The Devcon schedule is live!
  • TD Sequential Flashes Buy Signals for These 2 Popular Altcoins
  • The Bear Market Divergence That Shows What’s Really Going On With Bitcoin
  • Allocation Update – Q3 2024
Facebook X (Twitter) Instagram YouTube
Finance Insider Today
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
    • Mining
  • Stocks
  • Forex
  • Personal Finance
  • World Economy
  • AI in Finance
  • Commodities
  • DeFi
  • Fintech
  • NFTs
  • Learn Finance
Finance Insider Today
Home » Cryptocurrency
Cryptocurrency

Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed

FIT Editorial TeamBy FIT Editorial TeamMarch 22, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Beyond the official page itself, experts warned it lacked a proper sitemap, making it easy to clone and weaponize on lookalike domains.

Coinbase has taken down a recently flagged “legacy recovery” tool after on-chain investigators warned that it could be used to trick users into giving up their seed phrases.

The episode reignited concerns about how design choices for platforms may clash with longstanding security practices.

Table of Contents

Toggle
  • Security Concerns Over Coinbase Recovery Page
    • You may also like:
  • Social Engineering Risks

Security Concerns Over Coinbase Recovery Page

It all started on March 18, when Cos, founder of SlowMist, a blockchain security firm, asked why a Coinbase-hosted page was asking users to type in their 12-word recovery phrases in plain text. Cos shared screenshots showing a Coinbase Commercial withdrawal interface that required people to paste their mnemonic phrase while also suggesting they get it from Google Drive backups.

Shortly after, well-known on-chain investigator ZachXBT posted that the page could be used by attackers as a social engineering tool, given that it was hosted on an official Coinbase domain.

“So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” he asked.

Another member of the SlowMist team, 23pds, pointed out technical flaws on the page, saying that it didn’t have a proper sitemap and could be easily cloned. They added that attackers could copy the interface and use domains that look like it to trick people into giving them sensitive information.

There were also concerns beyond the risk of cloning, with one X user, going by Kieran, arguing that the bigger problem was behavioral. They claimed that the tool went against one of the most widely taught safety rules in crypto, which is to never share or enter a recovery phrase into a website. The existence of such requirements on official pages, according to them, could make phishing attempts more convincing.

Alex, a team member at Coinbase, responded by stating that they had removed the tool and were actively developing a new solution.

You may also like:

“Appreciate you all raising this and holding us to the highest standards,” they added.

At the time of writing, a check on the page showed that it had indeed been taken down, with a simple message informing users that the service was unavailable and that they should try again later.

Social Engineering Risks

The concerns raised by ZachXBT and the SlowMist team aren’t for nothing. Recent data shows that there is a shift in how bad actors are carrying out crypto-related attacks nowadays.

According to on-chain security company Nominis, in February, total losses related to cryptocurrency scams and exploits fell by nearly 87%. But more importantly, Nominis revealed that attackers are now more likely to target users instead of exploiting code.

The firm noted that recent incidents had relied more heavily on phishing and misleading prompts instead of technical vulnerabilities. And with such schemes becoming more common, it’s vital to deny attackers the sort of advantage ZachXBT believes occurrences like the Coinbase recovery tool could have possibly given them.

SPECIAL OFFER (Exclusive)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!



Source link

⚠️ Investment Disclaimer
The content published on Finance Insider Today is for informational and educational purposes only. It does not constitute financial advice, investment advice, or any other form of professional advice. Always conduct your own research and consult a qualified financial advisor before making any investment decisions. Finance Insider Today is not responsible for any financial losses resulting from decisions made based on information published on this website. Past performance is not indicative of future results. Financial markets carry significant risk. Never invest more than you can afford to lose.
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
FIT Editorial Team

Related Posts

TD Sequential Flashes Buy Signals for These 2 Popular Altcoins

March 22, 2026

Inside Ripple’s Massive 2026 Industry Survey

March 22, 2026

Grayscale Files S-1 to Launch HYPE ETF on Nasdaq

March 21, 2026

Elevate Your BTC by Integrating Bitcoin Everlight Shards Early

March 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum’s Metrics Shift, BTC Whale Moves & Altcoin Shakeups

September 10, 2025

AI Founder Puts XRP Price As High As $20-$30

July 2, 2025

Pro-XRP Attorney Reveals Why Ethereum Is A Bigger Winner Of The GENIUS Act Over Ripple

August 5, 2025

Is Pepe Ready to Explode? Whales Load Up 23 Trillion Tokens

February 12, 2026

From ‘Magic Money’ to Global Asset

January 4, 2026
CurrencyPrice
UAE Dirham 
UAE Dirham
3.6725
Australian Dollar 
Australian Dollar
1.4232down
Canadian Dollar 
Canadian Dollar
1.3723up
Swiss Franc 
Swiss Franc
0.788down
Renminbi 
Renminbi
6.8847up
Euro 
Euro
0.8632up
British Pound 
British Pound
0.7496down
Japanese Yen 
Japanese Yen
159.2345down
Malaysian Ringgit 
Malaysian Ringgit
3.9352down
New Zealand Dollar 
New Zealand Dollar
1.7147up
US Dollar 
US Dollar
1
22 Mar · FX Source: CurrencyRate 
CurrencyRate.Today
Check: 22 Mar 2026 00:50 UTC
Latest change: 22 Mar 2026 00:43 UTC
API: CurrencyRate
Disclaimers. This plugin or website cannot guarantee the accuracy of the exchange rates displayed. You should confirm current rates before making any transactions that could be affected by changes in the exchange rates.
⚡You can install this WP plugin on your website from the WordPress official website: Exchange Rates🚀
Categories
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Forex
  • Mining
  • Personal Finance
  • Stocks
  • World Economy
About us

Finance Insider Today is an independent financial news platform covering global markets, cryptocurrency, economy, fintech, and personal finance. Published daily.

Top Insights

$105 Breakout Or Double-Pair Collapse Ahead?

March 22, 2026

Six weeks until Devcon SEA in Bangkok

March 22, 2026

Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed

March 22, 2026
Categories
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Forex
  • Mining
  • Personal Finance
  • Stocks
  • World Economy
X (Twitter) Instagram YouTube
  • About us
  • Contact us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
Copyright © 2026 Financeinsidertoday.com All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.