SlowMist identifies critical security flaw on Coinbase Commerce where users are prompted to enter plaintext mnemonic phrases for asset recovery.
Regulation & Gov ·
SlowMist, a blockchain security firm, identified a critical vulnerability on Coinbase Commerce's Withdraw page where the interface directly solicits users to enter their plaintext mnemonic phrases for asset recovery. According to the disclosure, the page instructs users to retrieve the phrase from Google Drive, copy it, and paste it into a text field—a practice that exposes private key material to the browser and potential interception.
Storing and transmitting mnemonic phrases in plaintext contradicts fundamental cryptocurrency security practices. Such an approach creates multiple vectors for compromise, including browser history logging, clipboard exposure, and man-in-the-middle interception. Users following these instructions would effectively surrender their seed phrases to the platform and any network observer.
The scope of affected accounts and the timeline for remediation remain unclear. Coinbase Commerce has not issued a public response to the report at time of writing, and the specific conditions under which users encounter this prompt—whether limited to particular account types or recovery scenarios—have not been detailed.