Beyond the official page itself, experts warned it lacked a proper sitemap, making it easy to clone and weaponize on lookalike domains.Beyond the official page itself, experts warned it lacked a proper sitemap, making it easy to clone and weaponize on lookalike domains.

Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed

2026/03/22 06:43
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

Coinbase has taken down a recently flagged “legacy recovery” tool after on-chain investigators warned that it could be used to trick users into giving up their seed phrases.

The episode reignited concerns about how design choices for platforms may clash with longstanding security practices.

Security Concerns Over Coinbase Recovery Page

It all started on March 18, when Cos, founder of SlowMist, a blockchain security firm, asked why a Coinbase-hosted page was asking users to type in their 12-word recovery phrases in plain text. Cos shared screenshots showing a Coinbase Commercial withdrawal interface that required people to paste their mnemonic phrase while also suggesting they get it from Google Drive backups.

Shortly after, well-known on-chain investigator ZachXBT posted that the page could be used by attackers as a social engineering tool, given that it was hosted on an official Coinbase domain.

Another member of the SlowMist team, 23pds, pointed out technical flaws on the page, saying that it didn’t have a proper sitemap and could be easily cloned. They added that attackers could copy the interface and use domains that look like it to trick people into giving them sensitive information.

There were also concerns beyond the risk of cloning, with one X user, going by Kieran, arguing that the bigger problem was behavioral. They claimed that the tool went against one of the most widely taught safety rules in crypto, which is to never share or enter a recovery phrase into a website. The existence of such requirements on official pages, according to them, could make phishing attempts more convincing.

Alex, a team member at Coinbase, responded by stating that they had removed the tool and were actively developing a new solution.

At the time of writing, a check on the page showed that it had indeed been taken down, with a simple message informing users that the service was unavailable and that they should try again later.

Social Engineering Risks

The concerns raised by ZachXBT and the SlowMist team aren’t for nothing. Recent data shows that there is a shift in how bad actors are carrying out crypto-related attacks nowadays.

According to on-chain security company Nominis, in February, total losses related to cryptocurrency scams and exploits fell by nearly 87%. But more importantly, Nominis revealed that attackers are now more likely to target users instead of exploiting code.

The firm noted that recent incidents had relied more heavily on phishing and misleading prompts instead of technical vulnerabilities. And with such schemes becoming more common, it’s vital to deny attackers the sort of advantage ZachXBT believes occurrences like the Coinbase recovery tool could have possibly given them.

The post Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed appeared first on CryptoPotato.

Piyasa Fırsatı
Confidential Layer Logosu
Confidential Layer Fiyatı(CLONE)
$0.006374
$0.006374$0.006374
-5.84%
USD
Confidential Layer (CLONE) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption

Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption

The post Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption appeared on BitcoinEthereumNews.com. In brief Coinbase has filed a letter with the DOJ urging federal preemption of state crypto laws, citing Oregon’s securities suit, New York’s ETH stance, and staking bans. Chief Legal Officer Paul Grewal called state actions “government run amok,” warning that patchwork enforcement “slows innovation and harms consumers.” A legal expert told Decrypt that states risk violating interstate commerce rules and due process, and DOJ support for preemption may mark a potential turning point. Coinbase has gone on the offensive against state regulators, petitioning the Department of Justice that a patchwork of lawsuits and licensing schemes is tearing America’s crypto market apart. “When Oregon can sue us for services that are legal under federal law, something’s broken,” Chief Legal Officer Paul Grewal tweeted on Tuesday. “This isn’t federalism—this is government run amok.” When Oregon can sue us for services that are legal under federal law, something’s broken. This isn’t federalism–this is government run amok. We just sent a letter to @TheJusticeDept urging federal action on crypto market structure to remedy this. 1/3 — paulgrewal.eth (@iampaulgrewal) September 16, 2025 Coinbase’s filing says that states are “expansively interpreting their securities laws in ways that undermine federal law” and violate the dormant Commerce Clause by projecting regulatory preferences beyond state borders. “The current patchwork of state laws isn’t just inefficient – it slows innovation and harms consumers” and demands “federal action on crypto market structure,” Grewal said.  States vs. Coinbase It pointed to Oregon’s securities lawsuit against the exchange, New York’s bid to classify Ethereum as a security, and cease-and-desist orders on staking as proof that rogue states are trying to resurrect the SEC’s discredited “regulation by enforcement” playbook. Oregon Attorney General Dan Rayfield sued Coinbase in April for promoting unregistered securities, and in July asked a federal judge to return the…
Paylaş
BitcoinEthereumNews2025/09/18 11:52
Time Management For Entrepreneurs

Time Management For Entrepreneurs

When you’re managing everything on your own, time is your biggest asset. Yet while most entrepreneurs focus on leadership, growth and networking, they often overlook
Paylaş
Techbullion2026/03/24 20:21
Vitalik Buterin lays out new Ethereum roadmap at EDCON

Vitalik Buterin lays out new Ethereum roadmap at EDCON

The post Vitalik Buterin lays out new Ethereum roadmap at EDCON appeared on BitcoinEthereumNews.com. At EDCON 2025 in Osaka, Ethereum co-founder Vitalik Buterin delivered fresh details of Ethereum’s technical roadmap, delineating both short-term scaling goals and longer-term protocol transformations. The immediate priority, according to slides from the presentation, is scaling at the L1 level by raising the gas limit while maintaining decentralization. Tools such as block-level access lists, ZK-EVMs, gas repricing, and slot optimization were highlighted as means to improve throughput and efficiency. A central theme of the presentation was privacy, divided into protections for on-chain “writes” (transactions, voting, DeFi operations) and “reads” (retrieving blockchain state). Write privacy could be achieved through client-side zero-knowledge proofs, encrypted voting, and mixnet-based transaction relays. Read privacy efforts include trusted execution environments, private information retrieval techniques, dummy queries to obscure access patterns, and partial state nodes that reveal only necessary data. These measures aim to reduce information leakage across both ends of user interaction. In the medium term, Ethereum’s focus shifts to cross-Layer-2 interoperability. Vitalik described trustless L2 asset transfers, proof aggregation, and faster settlement mechanisms as key milestones toward a seamless rollup ecosystem. Faster slots and stronger finality, supported by techniques like erasure coding and three-stage finalization (3SF), are also in scope to enhance responsiveness and security. The roadmap also includes Stage 2 rollup advancements to strengthen verification efficiency, alongside a call for broader community participation to help build and maintain these improvements. The long-term “Lean Ethereum” blueprint emphasizes security, simplicity and optimization, with ambitions for quantum-resistant cryptography, formal verification of the protocol, and adoption of ideal primitives for hashing, signatures, and zero-knowledge proofs. Buterin stressed that these improvements are not just for scalability but to make Ethereum a stable, trustworthy foundation for the broader decentralized ecosystem. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication.…
Paylaş
BitcoinEthereumNews2025/09/18 03:22