[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

The Coinbase Commerce page requires users to enter a mnemonic phrase, raising security concerns

Mar 19, 2026 22:09:49

Share to

According to Cointelegraph, a subdomain page of Coinbase Commerce prompted users to enter their wallet recovery phrases, raising concerns among security researchers. SlowMist Yu Sin stated that it is incomprehensible why Coinbase would set up such a page, directly asking users to input their recovery phrases in plain text for asset recovery, believing this action poses serious security risks.

On-chain analyst ZachXBT pointed out that this page was previously referenced in a help document for Coinbase's Commerce product, which suggested users recover funds by importing their recovery phrases into compatible wallets like Coinbase Wallet or MetaMask, and included a link to the withdrawal tool on that subdomain. Currently, the help document is shown as deleted. ZachXBT also noted that if this page were exploited by malicious actors, it could facilitate social engineering attacks on Coinbase users targeting their recovery phrases.

Recent Fundraising

More
$14M Mar 17
-- Mar 17
-- Mar 17

New Tokens

More
Mar 13
Mar 11
Mar 8

Latest Updates on 𝕏

More
Mar 17
Mar 17
Mar 17