Coinbase is directing some Commerce users to a seed-phrase recovery flow ahead of a March 31 migration deadline. The issue sits inside Coinbase’s shutdown plan Coinbase is directing some Commerce users to a seed-phrase recovery flow ahead of a March 31 migration deadline. The issue sits inside Coinbase’s shutdown plan

Coinbase tells users to follow ‘foolish’ steps scammers use to withdraw funds from wallets

2026/03/20 04:05
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Coinbase is directing some Commerce users to a seed-phrase recovery flow ahead of a March 31 migration deadline.

The issue sits inside Coinbase’s shutdown plan for legacy Commerce wallets. In its transition guide, Coinbase says users with funds in a Commerce wallet must withdraw them before March 31, 2026, when the Commerce portal and withdrawal tool will become inaccessible.

For users who backed up their wallet to Google Drive, Coinbase says they should go to the Commerce dashboard, open Settings and Security, reveal the 12-word seed phrase, and use the withdrawal tool at withdraw.commerce.coinbase.com.

Coinbase says the process is especially important for merchants that received Bitcoin or other UTXO-based assets because balances may otherwise be hard to surface in standard wallets.

A seed phrase is the master recovery key for a self-custody wallet. Coinbase’s own wallet documentation describes it as a 12-word recovery phrase that only the user has access to.

Whoever controls that phrase controls access to the wallet and its funds. Lose it, and access to funds can be lost. Expose it, and funds in the wallet can be drained.

That is where the contradiction becomes hard to miss. Coinbase’s wallet guidance tells users never to share a recovery phrase, says the firm will never ask for it, and adds a separate warning: “Never paste it into any website.”

Yet the Commerce transition guide tells some users to reveal the same phrase as part of an official Coinbase-hosted recovery path.

The company’s explanation is that Commerce wallets are self-custodial, and Coinbase does not have access to the phrase or the funds, which leaves users responsible for recovery before the shutdown.

Security researchers see a phishing template

Nonetheless, this Coinbase demand has rung the alarm bells for many security experts, who are criticizing the platform for the behavior its page teaches users to accept.

Blockchain security firm SlowMist founder Yu Xian said he was puzzled that Coinbase would host a page asking users to enter a mnemonic phrase in plain text for asset recovery and said the practice was so insecure that he first wondered whether the subdomain had been hacked.

The warning sharpened the core criticism around the page: an official brand, an urgent deadline, and a seed-phrase workflow combine into a format attackers regularly mimic.

Meanwhile, SlowMist chief information security officer 23pds wrote on X that there were “two issues” with the flow. First, he said:

Secondly, he noted that the site had a flawed sitemap that could let attackers copy the front end and deploy a near-clone on a lookalike domain, creating a strong phishing lure for users already primed to trust the Coinbase version.

Additionally, blockchain investigator ZachXBT further pressed on that point even more directly. In a post on X, he wrote:

Their concerns are unsurprising, considering phishing and social engineering scams remain one of the most potent attack vectors against the crypto industry.

Last year, ZachXBT revealed that Coinbase users lose more than $300 million annually due to social engineering scams.

This captures why the Commerce flow has triggered such a strong reaction. Security teams have spent years teaching users that any request involving a seed phrase is the start of a scam.

However, a Coinbase-owned page handling the same phrase could change the visual and behavioral cues users have been taught to rely on.

Coinbase’s breach history hangs over the debate

Meanwhile, the security debate lands harder because Coinbase is already dealing with the aftereffects of past social-engineering incidents.

In May 2025, Coinbase reported that cybercriminals bribed a group of overseas support agents to steal customer data for social-engineering attacks.

The Brian Armstrong-led exchange said the attackers obtained account data for fewer than 1% of monthly transacting users and used it to compile lists of customers they could contact, pretending to be from the platform.

The company said no private keys were exposed and pledged to reimburse customers who were tricked into sending funds to attackers.

Apart from that, the company also has an earlier breach record.

Coinbase said in its 2024 annual report that in 2021, third parties obtained login credentials and personal information for at least 6,000 customers and used those details to exploit a vulnerability in the account recovery process. The firm said it reimbursed impacted customers about $25.1 million.

That history raises the stakes around any official workflow that asks users to handle a seed phrase on a live web page.

Security researchers warn that such a branded interface that normalizes seed-phrase entry will further boost phishing and impersonation attacks, which remain among the industry’s most effective attack methods.

The post Coinbase tells users to follow ‘foolish’ steps scammers use to withdraw funds from wallets appeared first on CryptoSlate.

Market Opportunity
FLOW Logo
FLOW Price(FLOW)
$0.03061
$0.03061$0.03061
-1.19%
USD
FLOW (FLOW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise

China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise

The post China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise appeared on BitcoinEthereumNews.com. China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise China’s internet regulator has ordered the country’s biggest technology firms, including Alibaba and ByteDance, to stop purchasing Nvidia’s RTX Pro 6000D GPUs. According to the Financial Times, the move shuts down the last major channel for mass supplies of American chips to the Chinese market. Why Beijing Halted Nvidia Purchases Chinese companies had planned to buy tens of thousands of RTX Pro 6000D accelerators and had already begun testing them in servers. But regulators intervened, halting the purchases and signaling stricter controls than earlier measures placed on Nvidia’s H20 chip. Image: Nvidia An audit compared Huawei and Cambricon processors, along with chips developed by Alibaba and Baidu, against Nvidia’s export-approved products. Regulators concluded that Chinese chips had reached performance levels comparable to the restricted U.S. models. This assessment pushed authorities to advise firms to rely more heavily on domestic processors, further tightening Nvidia’s already limited position in China. China’s Drive Toward Tech Independence The decision highlights Beijing’s focus on import substitution — developing self-sufficient chip production to reduce reliance on U.S. supplies. “The signal is now clear: all attention is focused on building a domestic ecosystem,” said a representative of a leading Chinese tech company. Nvidia had unveiled the RTX Pro 6000D in July 2025 during CEO Jensen Huang’s visit to Beijing, in an attempt to keep a foothold in China after Washington restricted exports of its most advanced chips. But momentum is shifting. Industry sources told the Financial Times that Chinese manufacturers plan to triple AI chip production next year to meet growing demand. They believe “domestic supply will now be sufficient without Nvidia.” What It Means for the Future With Huawei, Cambricon, Alibaba, and Baidu stepping up, China is positioning itself for long-term technological independence. Nvidia, meanwhile, faces…
Share
BitcoinEthereumNews2025/09/18 01:37
Uphold’s Massive 1.59 Billion XRP Holdings Shocks Community, CEO Reveals The Real Owners

Uphold’s Massive 1.59 Billion XRP Holdings Shocks Community, CEO Reveals The Real Owners

Uphold, a cloud-based digital financial service platform, has come under the spotlight after on-chain data confirmed that it safeguards approximately 1.59 billion XRP. According to Uphold’s Chief Executive Officer (CEO), Simon McLoughlin, these tokens are fully owned by customers, not the exchange itself.  Uphold Clarifies Massive XRP Holdings The crypto community was taken by surprise […]
Share
Bitcoinist2025/09/18 00:30