Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Coinbase Commerce Faces Backlash Over ‘Unsafe’ Seed Phrase Tool

The exchange asks merchants to enter seed phrases for wallet recovery, a practice experts warn is dangerously unsafe during platform migration.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: March 19, 2026 11:29 AM
Published 2026-03-19
Share
Coinbase Commerce Faces Backlash Over 'Unsafe' Seed Phrase Tool

Key Highlights

  • Coinbase’s seed phrase page sparks security fears; experts warn users against typing phrases online.
  • Merchants should use the official Commerce withdrawal tool to safely move funds before March 31, 2026.
  • Rising hacker threats, including North Korean attacks, make cautious crypto practices more urgent than ever.

Coinbase is facing criticism from the cybersecurity community following the launch of its new merchant recovery tool. The controversy stems from the tool’s requirement that users enter their seed phrases on the Commerce withdrawal page—an approach widely viewed as a significant security risk.

The page at ‘withdraw.commerce.coinbase.com/seed-phrase’ allows merchants to recover legacy self-custodial wallets during the platform’s migration to Coinbase Business by March 31, 2026. Coinbase suggests merchants can sign into Google Drive to copy and paste their mnemonic phrases, a practice cybersecurity experts call dangerously unsafe.

Experts quickly flagged the page as a potential vector for social engineering attacks. SlowMist Founder Cos described the behavior as “extremely unsafe,” stating the page “directly asks users to enter their plaintext mnemonic phrase for asset recovery. This is truly baffling.” 

我很疑惑 Coinbase 为什么会有这样的页面,直接让用户输入明文助记词做资产恢复?如此不安全的行为,匪夷所思…@coinbase 我都差点以为子域名被黑了…cc @im23pds https://t.co/NsBd223xWY pic.twitter.com/oBrp5UGQ8U

— Cos(余弦)😶‍🌫️ (@evilcos) March 19, 2026

Similarly, pseudonymous investigator ZachXBT highlighted that threat actors could exploit the page to target users via seed phrase scams. The situation has prompted calls for Coinbase to remove or revise the tool immediately.

Security risks and user guidance

Coinbase is combining its Commerce platform with Coinbase Business, and merchants now have two ways to move their funds. The safer choice is the Commerce withdrawal tool, which bundles payments into a single transfer. 

“For many merchants, especially those receiving Bitcoin or other UTXO-based assets, we highly recommend using the Commerce withdrawal tool before March 31, 2026,” the company said. The other option lets users enter their seed phrases directly into wallets like Coinbase Wallet or MetaMask.

Experts caution that typing seed phrases online—even on official sites—can put funds at risk. Slomist’s 23pds pointed out that the page’s structure could let attackers copy it and trick users with fake sites. 

Broader cybersecurity context

The frustration over Coinbase’s seed phrase portal is compounded by a dramatic escalation in sophisticated cyber threats. State-sponsored hackers, particularly from North Korea (DPRK), have evolved beyond simple phishing, increasingly posing as remote IT developers to infiltrate crypto companies from the inside.

This exact threat vector forced Coinbase to mandate in-person US-based training for employees handling sensitive systems last year in August, with CEO Brian Armstrong bluntly warning, “DPRK is very interested in stealing crypto.”

Previous cases, like the Base blockchain hack in which 55 WETH was stolen due to unverified smart contracts, have also demonstrated the risks of untested smart contracts and poor management of assets. Together with the insecure withdrawal systems, the changing tactics of hackers underscore the need for caution among cryptocurrency holders.

Coinbase users should stick to the official withdrawal tool and avoid typing their seed phrases online. Until the platform fixes the process, using third-party wallets or keeping funds in local, secure storage is a safer way to protect digital assets.

Also Read: Upbit Hacker Moves $16K in RAY Token After Weeks of Silence

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Coinbase
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Sr. Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Sen. Gillibrand's Son Bets on Perpetual Futures With $30M Raise
Sen. Gillibrand’s Son Bets on Perpetual Futures With $30M Raise

Find Us on Socials

You may also like

Coinbase CEO Illinois Crypto Tax Punishes Blockchain & Will Kill Tech Jobs

Coinbase CEO: Illinois Crypto Tax Punishes Blockchain & Will Kill Tech Jobs

Aztec Network’s RollupProcessor Exploited for $2.21 Million

Aztec Network’s RollupProcessor Exploited for $2.21 Million 

Little Boy Plus Loses $377K After Exploit Targets Minting Bug

Little Boy Plus Loses $377K as “No-Admin-Key” DeFi Protocol Gets Drained via Mint Bug

Fed Shock Hits Crypto Stocks as MSTR, COIN, MARA, BMNR Crash

Fed Shock Hits Crypto Stocks as MSTR, COIN, MARA, BMNR Crash

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information