The Coinbase Commerce page requires users to enter a mnemonic phrase, raising security concerns
According to Cointelegraph, a subdomain page of Coinbase Commerce prompted users to enter their wallet recovery phrases, raising concerns among security researchers. SlowMist Yu Sin stated that it is incomprehensible why Coinbase would set up such a page, directly asking users to input their recovery phrases in plain text for asset recovery, believing this action poses serious security risks.
On-chain analyst ZachXBT pointed out that this page was previously referenced in a help document for Coinbase's Commerce product, which suggested users recover funds by importing their recovery phrases into compatible wallets like Coinbase Wallet or MetaMask, and included a link to the withdrawal tool on that subdomain. Currently, the help document is shown as deleted. ZachXBT also noted that if this page were exploited by malicious actors, it could facilitate social engineering attacks on Coinbase users targeting their recovery phrases.
You may also like

Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack

The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future

When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB

The Power of Agency: The Agentic Wallet and the Next Decade of Wallets

Understanding x402 and MPP in One Article: Two Routes for Agent Payments

Particle Founder: The entrepreneurial insights I have gained the most from in the past year

Huang Renxun's latest podcast transcript: The future of Nvidia, the development of embodied intelligence and agents, the explosion of inference demand, and the public relations crisis of artificial intelligence

OKX Ventures Research Report: AI Agent Economic Infrastructure Research Report (Part 1)

The migration of settlement rights: B18 and the institutional starting point of on-chain banks

From Tencent and Circle: Looking at the Simple and Difficult Questions of Investment

The second half of stablecoins no longer belongs to the crypto circle

Cursor "Shell" Kimi Controversy Reversed: From Copyright Infringement Allegations to Authorized Collaboration, China's Open Source Model Once Again Becomes a Global AI Foundation

The Real Reason Tokens Don't Sell: 90% of Crypto Projects Overlook Investor Relations

Is the income of pump.fun real, earning a million dollars a day despite the market downturn?

The real reason why tokens are not selling: 90% of crypto projects neglect investor relations

Who is the true winner of the "Tokenization" narrative?

Moss: The Era of AI-Traded by Anyone | Project Introduction
