Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Coinbase Commerce Faces Backlash Over ‘Unsafe’ Seed Phrase Tool

The exchange asks merchants to enter seed phrases for wallet recovery, a practice experts warn is dangerously unsafe during platform migration.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2026-03-19
Make The Crypto Times preferred on GoogleGoogle
Coinbase Commerce Faces Backlash Over 'Unsafe' Seed Phrase Tool

Key Highlights

  • Coinbase’s seed phrase page sparks security fears; experts warn users against typing phrases online.
  • Merchants should use the official Commerce withdrawal tool to safely move funds before March 31, 2026.
  • Rising hacker threats, including North Korean attacks, make cautious crypto practices more urgent than ever.

Coinbase is facing criticism from the cybersecurity community following the launch of its new merchant recovery tool. The controversy stems from the tool’s requirement that users enter their seed phrases on the Commerce withdrawal page—an approach widely viewed as a significant security risk.

The page at ‘withdraw.commerce.coinbase.com/seed-phrase’ allows merchants to recover legacy self-custodial wallets during the platform’s migration to Coinbase Business by March 31, 2026. Coinbase suggests merchants can sign into Google Drive to copy and paste their mnemonic phrases, a practice cybersecurity experts call dangerously unsafe.

Experts quickly flagged the page as a potential vector for social engineering attacks. SlowMist Founder Cos described the behavior as “extremely unsafe,” stating the page “directly asks users to enter their plaintext mnemonic phrase for asset recovery. This is truly baffling.” 

我很疑惑 Coinbase 为什么会有这样的页面,直接让用户输入明文助记词做资产恢复?如此不安全的行为,匪夷所思…@coinbase 我都差点以为子域名被黑了…cc @im23pds https://t.co/NsBd223xWY pic.twitter.com/oBrp5UGQ8U

— Cos(余弦)😶‍🌫️ (@evilcos) March 19, 2026

Similarly, pseudonymous investigator ZachXBT highlighted that threat actors could exploit the page to target users via seed phrase scams. The situation has prompted calls for Coinbase to remove or revise the tool immediately.

Security risks and user guidance

Coinbase is combining its Commerce platform with Coinbase Business, and merchants now have two ways to move their funds. The safer choice is the Commerce withdrawal tool, which bundles payments into a single transfer. 

“For many merchants, especially those receiving Bitcoin or other UTXO-based assets, we highly recommend using the Commerce withdrawal tool before March 31, 2026,” the company said. The other option lets users enter their seed phrases directly into wallets like Coinbase Wallet or MetaMask.

Experts caution that typing seed phrases online—even on official sites—can put funds at risk. Slomist’s 23pds pointed out that the page’s structure could let attackers copy it and trick users with fake sites. 

Broader cybersecurity context

The frustration over Coinbase’s seed phrase portal is compounded by a dramatic escalation in sophisticated cyber threats. State-sponsored hackers, particularly from North Korea (DPRK), have evolved beyond simple phishing, increasingly posing as remote IT developers to infiltrate crypto companies from the inside.

This exact threat vector forced Coinbase to mandate in-person US-based training for employees handling sensitive systems last year in August, with CEO Brian Armstrong bluntly warning, “DPRK is very interested in stealing crypto.”

Previous cases, like the Base blockchain hack in which 55 WETH was stolen due to unverified smart contracts, have also demonstrated the risks of untested smart contracts and poor management of assets. Together with the insecure withdrawal systems, the changing tactics of hackers underscore the need for caution among cryptocurrency holders.

Coinbase users should stick to the official withdrawal tool and avoid typing their seed phrases online. Until the platform fixes the process, using third-party wallets or keeping funds in local, secure storage is a safer way to protect digital assets.

Also Read: Upbit Hacker Moves $16K in RAY Token After Weeks of Silence

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Coinbase
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Aave Labs and MiCA regulation logos with a MiCA Review Consultation document under European Commission oversight
Aave Urges EU to Rethink MiCA Rules for DeFi and Stablecoins
White Bitget exchange logo overlaying a dark mountain peak background
Bitget Alliance Program Reward Pool Tops $1.9M in Three Days After $387.5M Hack
Glowing Aave logo with digital glitch effect set against a dark purple background
Aave v3 Loop Module Hacked for 114 ETH; Aave’s Pools Not Affected
International Monetary Fund IMF signage displayed on a blue wall in multiple languages
IMF Waives El Salvador’s Bitcoin Breach, Approves $138M Disbursement
Gold Bitcoin BTC coin standing upright with autumn leaves and a fluctuating crypto trading chart background
Bitcoin’s Q4 Open: Price Recovery Structure Holds, Breakout Above $87,400 Still Missing

Find Us on Socials

You may also like

Uranium Finance Trial Opens as Prosecutors Tell Jury $53 Million Drain Was Spalletta's Work

Uranium Finance Trial Opens as Prosecutors Tell Jury $53 Million Drain Was Spalletta’s Work

Ostium $23.75M Hack Recovery 3,321 Wallets Repaid, 345 LPs Face $1,000 Choice

Ostium $23.75M Hack Recovery: 3,321 Wallets Repaid, 345 LPs Face $1,000 Choice

Morpho Liquidity Drop Triggers Shift DeFi USDC Vault Exit, No Loss as Deposits Pause

Morpho Liquidity Drop Triggers Shift DeFi USDC Vault Exit, No Loss as Deposits Pause

The DogeOS logo featuring a Shiba Inu icon on a yellow app-style badge alongside black block typography over a luminous network background.

DogeOS Launches Testnet to Bring DeFi Apps to Dogecoin

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information