Coinbase Sparks Panic
While the crypto market is evolving in a bullish rally context, a major controversy has hit Coinbase. As part of the migration between Coinbase Commerce and Coinbase Business, the exchange has put online a fund recovery page asking users to enter their 12-word seed phrase. A practice strictly prohibited in the Web3 ecosystem.
The alert was raised by Evilcos, founder of SlowMist, who immediately suspected a site hack. Indeed, requesting a recovery phrase in plain text is typically associated with phishing. This discovery sent shockwaves through the community, as this practice goes against the most basic security rules.
The confusion is total. How can an actor as established as Coinbase expose its users to such risk? Even though the platform recommends using a secure automated tool, the presence of this manual option is enough to create a climate of FUD and undermine investor confidence.
Social Engineering: An Ideal Flaw for Hackers
On-chain analyst ZachXBT quickly amplified the situation, highlighting a critical social engineering risk. Unlike classic attacks, scammers can now rely on an official Coinbase page, making their attempts much more credible and dangerous for users.
In a context of bull run, where investors are often rushed and less vigilant, this flaw becomes particularly critical. With the March 31, 2026 deadline, malicious actors could easily create a sense of urgency to push victims into revealing their seed phrase, resulting in a total and irreversible loss of their assets.
Coinbase is trying to reassure by highlighting its automated withdrawal system, supposedly protecting users without exposing their private keys. But maintaining this controversial page raises serious questions. This type of error could trigger a lasting confidence retracement toward the platform, at a time when security is becoming a central issue in the crypto market again.
Related Articles: