Thursday, March 19, 2026
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Coinbase instructs users to follow the same ‘foolish’ steps scammers use to withdraw funds from wallets

by DigestWire member
March 19, 2026
in Blockchain, Crypto Market, Cryptocurrency
0
Coinbase instructs users to follow the same ‘foolish’ steps scammers use to withdraw funds from wallets
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Coinbase is directing some Commerce users to a seed-phrase recovery flow ahead of a March 31 migration deadline.

The issue sits inside Coinbase’s shutdown plan for legacy Commerce wallets. In its transition guide, Coinbase says users with funds in a Commerce wallet must withdraw them before March 31, 2026, when the Commerce portal and withdrawal tool will become inaccessible.

For users who backed up their wallet to Google Drive, Coinbase says they should go to the Commerce dashboard, open Settings and Security, reveal the 12-word seed phrase, and use the withdrawal tool at withdraw.commerce.coinbase.com.

Coinbase says the process is especially important for merchants that received Bitcoin or other UTXO-based assets because balances may otherwise be hard to surface in standard wallets.

A seed phrase is the master recovery key for a self-custody wallet. Coinbase’s own wallet documentation describes it as a 12-word recovery phrase that only the user has access to.

Whoever controls that phrase controls access to the wallet and its funds. Lose it, and access to funds can be lost. Expose it, and funds in the wallet can be drained.

That is where the contradiction becomes hard to miss. Coinbase’s wallet guidance tells users never to share a recovery phrase, says the firm will never ask for it, and adds a separate warning: “Never paste it into any website.”

Yet the Commerce transition guide tells some users to reveal the same phrase as part of an official Coinbase-hosted recovery path.

The company’s explanation is that Commerce wallets are self-custodial, and Coinbase does not have access to the phrase or the funds, which leaves users responsible for recovery before the shutdown.

Security researchers see a phishing template

Nonetheless, this Coinbase demand has rung the alarm bells for many security experts, who are criticizing the platform for the behavior its page teaches users to accept.

Blockchain security firm SlowMist founder Yu Xian said he was puzzled that Coinbase would host a page asking users to enter a mnemonic phrase in plain text for asset recovery and said the practice was so insecure that he first wondered whether the subdomain had been hacked.

The warning sharpened the core criticism around the page: an official brand, an urgent deadline, and a seed-phrase workflow combine into a format attackers regularly mimic.

Meanwhile, SlowMist chief information security officer 23pds wrote on X that there were “two issues” with the flow. First, he said:

“While the link is from the official Coinbase website, directly asking users to transmit their mnemonic phrase to verify assets is extremely foolish.”

Secondly, he noted that the site had a flawed sitemap that could let attackers copy the front end and deploy a near-clone on a lookalike domain, creating a strong phishing lure for users already primed to trust the Coinbase version.

Additionally, blockchain investigator ZachXBT further pressed on that point even more directly. In a post on X, he wrote:

“So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?”

Their concerns are unsurprising, considering phishing and social engineering scams remain one of the most potent attack vectors against the crypto industry.

Last year, ZachXBT revealed that Coinbase users lose more than $300 million annually due to social engineering scams.

This captures why the Commerce flow has triggered such a strong reaction. Security teams have spent years teaching users that any request involving a seed phrase is the start of a scam.

However, a Coinbase-owned page handling the same phrase could change the visual and behavioral cues users have been taught to rely on.

Coinbase’s breach history hangs over the debate

Meanwhile, the security debate lands harder because Coinbase is already dealing with the aftereffects of past social-engineering incidents.

In May 2025, Coinbase reported that cybercriminals bribed a group of overseas support agents to steal customer data for social-engineering attacks.

The Brian Armstrong-led exchange said the attackers obtained account data for fewer than 1% of monthly transacting users and used it to compile lists of customers they could contact, pretending to be from the platform.

The company said no private keys were exposed and pledged to reimburse customers who were tricked into sending funds to attackers.

Apart from that, the company also has an earlier breach record.

Coinbase said in its 2024 annual report that in 2021, third parties obtained login credentials and personal information for at least 6,000 customers and used those details to exploit a vulnerability in the account recovery process. The firm said it reimbursed impacted customers about $25.1 million.

That history raises the stakes around any official workflow that asks users to handle a seed phrase on a live web page.

Security researchers warn that such a branded interface that normalizes seed-phrase entry will further boost phishing and impersonation attacks, which remain among the industry’s most effective attack methods.

The post Coinbase instructs users to follow the same ‘foolish’ steps scammers use to withdraw funds from wallets appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
Adam Back Confirmed As A Bitcoin 2026 Speaker

Adam Back Confirmed As A Bitcoin 2026 Speaker

Samara Weaving And The “Ready Or Not 2: Here I Come” Cast Reveal What They Stole From Set, And More

Samara Weaving And The "Ready Or Not 2: Here I Come" Cast Reveal What They Stole From Set, And More

Analyst Shares Dogecoin Quantitative Roadmap To New All-Time Highs, Here’s What It Says

Analyst Shares Dogecoin Quantitative Roadmap To New All-Time Highs, Here’s What It Says

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

4 Best Free Movies to Watch on YouTube, Pluto TV and More (March 2026)

Niall Horan Reveals New Song ‘End of an Era’ Is a Tribute to Liam Payne

Rebecca Gayheart Says She Still Has ‘No Words’ About Eric Dane’s Death

Woman Killed Sleeping Boyfriend, Dismembered Body Before Burying Him in Yard

‘Love Island’ Star Huda’s Boyfriend Claims Ex Won’t Let Him See His Son

Celebrity Deaths of 2026: Jordan Wright, Kiki Shepard and More

Trending

AEK Larnaca 1-2 Crystal Palace AET (Palace win 2-1 on aggregate): Sarr at the double to sink nine-man Cypriots
Football

AEK Larnaca 1-2 Crystal Palace AET (Palace win 2-1 on aggregate): Sarr at the double to sink nine-man Cypriots

by DigestWire member
March 19, 2026
0

Ismaila Sarr was the hero for Crystal Palace in Cyprus tonight

Midtjylland 1-2 Nottingham Forest AET (2-2 on agg, Forest win 3-0 on pens): Penalty pain for hosts as Pereira’s men squeeze through

Midtjylland 1-2 Nottingham Forest AET (2-2 on agg, Forest win 3-0 on pens): Penalty pain for hosts as Pereira’s men squeeze through

March 19, 2026
French Girls Are Obsessed With This Comfy Spring Style Over Jeans

French Girls Are Obsessed With This Comfy Spring Style Over Jeans

March 19, 2026
4 Best Free Movies to Watch on YouTube, Pluto TV and More (March 2026)

4 Best Free Movies to Watch on YouTube, Pluto TV and More (March 2026)

March 19, 2026
Niall Horan Reveals New Song ‘End of an Era’ Is a Tribute to Liam Payne

Niall Horan Reveals New Song ‘End of an Era’ Is a Tribute to Liam Payne

March 19, 2026
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • AEK Larnaca 1-2 Crystal Palace AET (Palace win 2-1 on aggregate): Sarr at the double to sink nine-man Cypriots March 19, 2026
  • Midtjylland 1-2 Nottingham Forest AET (2-2 on agg, Forest win 3-0 on pens): Penalty pain for hosts as Pereira’s men squeeze through March 19, 2026
  • French Girls Are Obsessed With This Comfy Spring Style Over Jeans March 19, 2026

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.