SlowMist Cos: Coinbase Commerce's withdrawal page exhibits extremely insecure behavior, directly prompting users to enter a mnemonic phrase in plaintext for asset recovery. This is utterly baffling. The page states: "Log in to Google Drive from the portal, copy the mnemonic phrase, and paste it into the text box below." ZachXBT: Malicious attackers could exploit this Coinbase page to socially engineer attacks using the mnemonic phrase. SlowMist also points out that attackers can easily use tools like ResourcesSaver to download the front-end code and deploy similar phishing websites.
Risk and Disclaimer:The content shared by the author represents only their personal views and does not reflect the position of CoinWorldNet (币界网). CoinWorldNet does not guarantee the truthfulness, accuracy, or originality of the content. This article does not constitute an offer, solicitation, invitation, recommendation, or advice to buy or sell any investment products or make any investment decisions
No Comments
edit
comment
collection31
like43
share