Back

Coinbase Page Asks Users for Seed Phrases — Security Researchers Sound Alarm

Prefer us on Google
author avatar

Written by
Kamina Bashir

19 March 2026 05:07 UTC
  • Coinbase Commerce's seed phrase withdrawal page is being called out by security researchers.
  • SlowMist founder described this as an unsafe practice.
  • The concern surfaces as Coinbase winds down Commerce ahead of its March 31 deadline.
Promo

Security researchers have raised alarms about an active Coinbase Commerce page that requires users to enter a 12-word seed phrase directly.

SlowMist’s founder, who uses the pseudonym Evilcos, posted a direct warning about the page, calling it an unsafe practice.

“I’m very puzzled why Coinbase would have such a page that directly asks users to enter their mnemonic phrase in plain text to recover assets. Such an unsafe practice is truly unbelievable…I almost thought the subdomain had been hacked,” he said.

Sponsored
Sponsored
Coinbase Commerce Seed Recover oage
Coinbase Seed Recovery Page. Source: Coinbase

Follow us on X to get the latest news as it happens

Blockchain investigator ZachXBT amplified the concern.

“So basically Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” he said.

For context, Social engineering scams are attacks where criminals manipulate people into revealing sensitive information or taking actions that compromise their security, rather than hacking systems directly. Instead of breaking through technical defenses, attackers exploit human psychology: trust, urgency, fear, or authority.

Coinbase is requiring users to move funds as it merges Commerce with Coinbase Business, with a March 31, 2026, deadline. It offers two withdrawal options. The first is a commerce withdrawal tool that consolidates funds into a single transaction. According to Coinbase, the tool handles the complexity of scanning a user’s Commerce addresses.

The exchange highlighted that this is the recommended method. Alternatively, users can use their seed phrase directly on the Coinbase page. 

“If you have your seed phrase, you can import it into a compatible wallet (like Coinbase Wallet or MetaMask),” the blog read. “For many merchants, especially those who received payments in Bitcoin or other UTXO-based assets, we highly recommend using the Commerce withdrawal tool prior to March 31, 2026.”

Coinbase did not immediately respond to BeInCrypto’s request for comment on this matter.

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.

Sponsored
Sponsored