Meet the Top 101 in Crypto
News
5 min read

Coinbase Security Warning: Commerce Page Prompts Users To Enter Seed Phrases

Published 19 March 2026
Prashant Jha
Authors
Edited by Insha Zia

Key Takeaways

  • Coinbase Commerce migration page asks users to enter seed phrases in plaintext, sparking major security concerns.
  • SlowMist & ZachXBT warn that it enables easy phishing and wallet drains during the shutdown rush.
  • No official Coinbase response yet; experts urge avoiding the page and using offline recovery methods.

Coinbase is in the final weeks of shutting down its long-running Coinbase Commerce platform, with a hard deadline of Mar. 31, 2026.

Merchants and users must transition everything to the new Coinbase Business service or risk losing access.

In the middle of this migration sits a withdrawal recovery page that has security researchers up in arms.

The page bluntly instructs users to “Enter your secret recovery phrase.”

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2018
Promotions
Deposit $100, Get an Extra $300 in GOLD!
Coins
Shiba Inu Bitcoin PAX Gold Ampleforth Ethereum +70
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Experience a 1-minute swap on a non-custodial platform.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
Show More

Coinbase Withdrawal Page Causes Community Uproar

Coinbase Commerce’s withdrawal page has become the center of attention for the crypto community, but for all the wrong reasons.

The page asks users to enter their seed phrase in plain text, creating a massive security risk.

It notes that when the Commerce account was created, users received a 12-word mnemonic (seed phrase) for their self-custodial wallet.

Coinbase Commerce.
Coinbase Commerce Withdrawal page. Credit: Coinbase.

The form then asks users to paste that exact phrase or even a private key into a plain-text field.

To make it “easier,” the site adds: “Sign in to Google Drive from the portal, copy the phrase, and paste it in the text field below.”

Collapsible help sections reinforce cloud backups, paper notes, or password managers as normal storage options.

Additionally, there is a recovery tool for legacy wallets during the shutdown.

In practice, it violates one of the most fundamental rules in cryptocurrency: never enter your seed phrase on any website.

Seed phrases are the master key to self-custodial funds.

Anyone who obtains the 12 words gains permanent, irreversible control—no password reset, no customer support intervention, no recovery.

Coinbase itself states in its help articles that “no one, not even Coinbase, can access your funds without the secret recovery phrase.”

Yet its own migration tool is asking users to hand that master key directly to a browser.

Coinbase has issued no public statement addressing the criticism of its seed-phrase page.

Neither its official X account nor its blog has commented on SlowMist’s analysis or ZachXBT’s concerns.

SlowMist and Crypto Community Sound Alarm

Security firm SlowMist was among the first to flag the page publicly on Mar. 19, calling the design “extremely unsafe behavior” and “truly baffling.”

The firm noted that the entire frontend can be downloaded with simple tools such as ResourcesSaver, enabling attackers to spin up pixel-perfect phishing clones in minutes.

Users who have been trained to trust anything under the coinbase.com domain could easily be tricked into visiting a fake version that looks identical.

Blockchain investigator ZachXBT amplified the warning the same day:

“So basically, Coinbase has an official page live threat actors can use to target Coinbase users via seed phrase social engineering if they wanted?” 

He noted that malicious actors could combine cloned sites with targeted DMs, fake support tickets, or even man-in-the-middle attacks on the legitimate page itself.

The danger is not theoretical; crypto users already lose hundreds of millions annually to seed-phrase phishing.

An official-looking Coinbase page that normalizes pasting the phrase makes social-engineering campaigns exponentially more effective. 

A single compromised browser extension, a malicious Wi-Fi network, or a cleverly timed pop-up could drain wallets instantly.

For merchants holding business funds, the financial impact could be existential.

The timing coincides with a high-pressure deadline. Merchants rushing to move assets before Mar. 31 are more likely to lower their guard, exactly the psychological state scammers exploit.

What Merchants and Users Should Do Right Now

The safest path is simple: treat the page as a last resort:

  • Export assets to a hardware wallet (Ledger, Trezor, etc.) or to a fresh, offline software wallet you control.

  • Never paste the seed phrase into any browser, even one you believe is official.

  • Verify every URL manually and avoid clicking links from DMs or emails.

  • If you cannot locate your original phrase, contact Coinbase support through official channels only.
  • Understand that without the mnemonic, funds may be permanently inaccessible, as the page itself warns.

This incident is a stark reminder that even the largest exchanges can introduce catastrophic UX choices under deadline pressure.

Self-custody means self-responsibility, and no convenience feature is worth risking your entire wallet.

The clock is ticking on Coinbase Commerce.

For the sake of user funds, the community hopes Coinbase will either disable the plaintext input immediately or provide a genuinely secure migration alternative before March 31.

Prashant Jha

Prashant Jha is a seasoned crypto journalist based in Delhi, India, with a Bachelor’s Degree in Computer Science Engineering. Passionate about the evolving world of blockchain and cryptocurrencies, he has been a dedicated voice in the industry since 2018. Prashant’s expertise lies in regulatory reporting, where he unravels complex legal and financial developments with clarity and precision. Before joining CCN in 2024, he honed his craft at Cointelegraph, establishing himself as a trusted name in crypto journalism.

His coverage spans major industry events, including the high-profile collapses of FTX, Three Arrows Capital (3AC), and LUNA, offering readers insightful analyses of their regulatory and market implications. Prashant’s technical background enables him to bridge the gap between intricate blockchain technology and its real-world applications, making his work accessible to novices and experts.

Beyond his professional pursuits, Prashant is an avid music enthusiast, often exploring diverse genres to unwind. A sports lover, he has a particular passion for cricket and frequently engages in discussions about the game. His multifaceted interests and sharp journalistic instincts make him a valuable contributor to CCN, where he continues shaping the crypto landscape's narrative.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status