ZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns.  A live page onZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns.  A live page on

Coinbase Page Flags Security Risk Over Seed Phrase Entry

2026/03/20 01:00
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

ZachXBT flags Coinbase Commerce recovery page asking users to enter their 12-word seed phrase, raising phishing and social engineering concerns. 

A live page on Coinbase’s official domain is drawing security alarm from researchers. The page, hosted at withdraw.commerce.coinbase.com, asks users to enter a 12-word seed phrase as part of an asset recovery process tied to Coinbase Commerce. The exchange has not pulled the page down.

On-chain investigator ZachXBT raised the alarm on X, questioning whether Coinbase had thought through what a page like this could enable. “So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” ZachXBT wrote. The post drew thousands of interactions almost immediately.

When an Official Page Becomes the Weapon

Security researcher evilcos flagged the same page earlier on X, saying the practice of asking users to input plaintext mnemonic phrases was simply hard to believe from a major exchange. The researcher said the subdomain initially looked like it had been compromised. It had not. The page is official.

The Coinbase Commerce help documentation, visible on the recovery page, explains the process. It tells merchants their funds may be spread across hundreds or even thousands of wallet addresses because Commerce generated a new address for every payment received. Importing the seed phrase into a standard wallet, it says, may not show the full balance. Standard wallets typically scan only the first 20 unused addresses. For Bitcoin and other UTXO-based assets, Coinbase directed users toward the withdrawal tool before March 31, 2026.

The documentation also instructs users on how to retrieve a seed phrase backed up to Google Drive, then enter it at the withdrawal tool. This is where researchers say the risk sits.

Two Separate Problems, One Very Dangerous Page

Security researcher im23pds posted on X breaking the concern into two distinct issues. First, even though the link originates from an official Coinbase domain, asking users to transmit their mnemonic phrase to verify assets is careless by any security standard. Second, the website has a flawed sitemap. Attackers could use tools like ResourcesSaver to download the front-end code entirely and deploy a near-identical copy. Pair that with a lookalike domain, and a Coinbase phishing campaign becomes significantly easier to run.

In a separate earlier post, im23pds noted on X that the page was built carelessly. The team launched it without even setting up a sitemap. That kind of oversight makes the page even more accessible to anyone wanting to copy its structure.

Source:  im23pds 

The core danger is straightforward. Threat actors do not need to break into Coinbase systems. They point a user at a fake version of an already-existing official page that asks for a seed phrase. The user, conditioned by the real page, hands it over.

The Broader Pattern Here

This is not a new pattern for the exchange. ZachXBT has previously documented how bad actors exploit Coinbase’s brand in social engineering campaigns, using impersonation and fake support channels to drain wallets. The Commerce recovery page, in this case, does the groundwork for scammers without anyone having to impersonate a thing.

The page remains live. Coinbase has not responded publicly to the concerns raised.

The post Coinbase Page Flags Security Risk Over Seed Phrase Entry appeared first on Live Bitcoin News.

Market Opportunity
Particl Logo
Particl Price(PART)
$0.1532
$0.1532$0.1532
+1.59%
USD
Particl (PART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

The post Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny appeared on BitcoinEthereumNews.com. The cryptocurrency world is buzzing with a recent controversy surrounding a bold OpenVPP partnership claim. This week, OpenVPP (OVPP) announced what it presented as a significant collaboration with the U.S. government in the innovative field of energy tokenization. However, this claim quickly drew the sharp eye of on-chain analyst ZachXBT, who highlighted a swift and official rebuttal that has sent ripples through the digital asset community. What Sparked the OpenVPP Partnership Claim Controversy? The core of the issue revolves around OpenVPP’s assertion of a U.S. government partnership. This kind of collaboration would typically be a monumental endorsement for any private cryptocurrency project, especially given the current regulatory climate. Such a partnership could signify a new era of mainstream adoption and legitimacy for energy tokenization initiatives. OpenVPP initially claimed cooperation with the U.S. government. This alleged partnership was said to be in the domain of energy tokenization. The announcement generated considerable interest and discussion online. ZachXBT, known for his diligent on-chain investigations, was quick to flag the development. He brought attention to the fact that U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce had directly addressed the OpenVPP partnership claim. Her response, delivered within hours, was unequivocal and starkly contradicted OpenVPP’s narrative. How Did Regulatory Authorities Respond to the OpenVPP Partnership Claim? Commissioner Hester Peirce’s statement was a crucial turning point in this unfolding story. She clearly stated that the SEC, as an agency, does not engage in partnerships with private cryptocurrency projects. This response effectively dismantled the credibility of OpenVPP’s initial announcement regarding their supposed government collaboration. Peirce’s swift clarification underscores a fundamental principle of regulatory bodies: maintaining impartiality and avoiding endorsements of private entities. Her statement serves as a vital reminder to the crypto community about the official stance of government agencies concerning private ventures. Moreover, ZachXBT’s analysis…
Share
BitcoinEthereumNews2025/09/18 02:13
Zano Surges 22% as Privacy Coins See Revival: Why ZANO is Trending Today

Zano Surges 22% as Privacy Coins See Revival: Why ZANO is Trending Today

Privacy-focused cryptocurrency Zano has surged 22% in the past 24 hours, reaching $9.41 with trading volume jumping to $1.87 million. We analyze the on-chain metrics
Share
Blockchainmagazine2026/03/20 21:06
Trump's latest foray condemned for heaping even more pain on farmers

Trump's latest foray condemned for heaping even more pain on farmers

Farmers across the country warned they cannot survive for much longer as the Iran war worsens the fuel and fertilizer stocks. Industry experts said that already
Share
Rawstory2026/03/20 21:45