Coinbase Seed Phrase Recovery Page Removed After Social Engineering Warnings
Coinbase has taken down a recently flagged “legacy recovery” tool after on-chain investigators warned it could be used for Coinbase seed phrase social engineering.
The issue began on March 18 when SlowMist founder Cos questioned why a Coinbase-hosted page asked users to type their 12-word recovery phrase (seed phrase) in plain text, including suggestions that users pull it from Google Drive backups. On-chain investigator ZachXBT then highlighted that the page—hosted on an official Coinbase domain—could be cloned and weaponized on lookalike sites to trick victims into submitting their Coinbase seed phrase.
SlowMist’s team (including 23pds) pointed to technical/design weaknesses, such as the lack of a proper sitemap, which made cloning easier. Separately, security commentators stressed the behavioral risk: users are widely taught never to enter recovery phrases into a website, and official-looking prompts can make phishing more convincing.
A Coinbase team member confirmed the tool was removed and said a new solution is under development. At the time of the report, the page displayed a service-unavailable message.
Broader context: Nominis reported that crypto scam and exploit losses fell by about 87% in February, but attackers are increasingly targeting users via phishing and misleading prompts rather than exploiting code—making prompt-level security and user-facing design critical.
Neutral
该消息主要是平台层面的安全事件(Coinbase 下架要求输入 seed phrase 的页面),对整体加密市场的直接价格影响有限,因此偏“中性”。对交易者而言,更现实的影响在于风险偏好与事件驱动情绪:
- 短期:若市场把它视为“监管/安全合规加强”的信号,可能降低对交易所相关资产或用户资金安全的担忧情绪;但也可能引发用户对交易所和恢复流程的警惕,从而带来短期情绪波动。
- 长期:Nominis 提到“损失下降但钓鱼更常见”,说明攻击面从技术漏洞转向用户交互与提示。此类平台下架与改版通常不改变行业基本面,但会强化“账户安全/助记词处理流程”作为长期安全标准,进而影响用户行为与平台策略。
类似事件里,真正会造成市场层面影响的往往是大规模资金损失或系统性故障;本次报道的重点是快速移除可疑工具,因此更可能是风险提示而非宏观利空。