Skip to content
btc Bitcoin $70,081 -1.73% eth Ethereum $2,140 -2.26% usdt Tether $1 0.01% xrp XRP $1 -0.83% bnb BNB $640 -1.37% usdc USDC $1 0.00% sol Solana $88 -1.52% trx TRON $0 -0.64% figr_heloc Figure Heloc $1 -0.55% doge Dogecoin $0 -1.47%

Coinbase under backlash for suspicious commerce page seeking user wallet info

Coinbase Commerce page requests seed phrases, raising security concerns
SHARE THIS ARTICLE

Coinbase has come under the public scanner over a suspicious commerce portal that many complain mimics a phishing attempt. Yu Xian, the founder of blockchain security firm SlowMist, is among those who have flagged this page on social media.

The page under question shows Coinbase asking users to punch-in their secret wallet recovery phrases. It reads, “when setting up your Commerce account, you were given a 12-word recovery phrase for your Commerce platform. Enter your recovery phase or private key.”

Anybody who engages with crypto wallets would know that ones wallet security phase of private key are never supposed to be shared.

Its the one cardinal rule for those saving their assets on web-connected hot wallets. So when this page under the Coinbase name started to surface, suspicions of a potential phishing attempt started to make rounds on social media.

Flagging the page Xian said, “I’m really puzzled why Coinbase would have a page like this, directly asking users to input their plaintext mnemonic phrases for asset recovery? Such an insecure practice is simply unbelievable…@coinbase. I almost thought the subdomain had been hacked.”

Xian also shared screenshots of the page as part of this tweet.

Popular Web3 scam investigator who goes by the username @ZachXBT also joined the conversation on X questioning Coinbase.

Coinbase under backlash for suspicious commerce page seeking user wallet info

Source: X/ @zachxbt

Coinbase is yet to respond to these ongoing complaints.

SlowMist-linked researcher who operates from the @im23pds handle on X has pointed out that the page is definitely linked to the official Coinbase website, however, the website linked to the page has a flawed sitemap that could let cyber threat actors to download the front-end code and deploy a similar website and execute a phishing attack.

An explanation from Coinbase on the matter remains awaited for now.

As per Chainalysis, over $14 billion was wired to addresses linked to scammers and fraudsters in 2025 who commonly restored to deploying phishing attacks on unsuspecting crypto investors.

Coin Headlines covers the latest news in crypto, blockchain, Web3, and markets, bringing you credible and up-to-date information on all the latest developments from around the world.

We focus on real-time news updates, market movements, whale transfers, and macroeconomic trends to keep you informed and engaged. Whether it’s Bitcoin price swings, altcoin updates, meme coin hype, regulatory changes, or major moves from the world of traditional finance, Coin Headlines gives you what you need to know, right when you need it.