Slow Fog CISO: The Coinbase Commerce asset recovery page sitemap also has flaws, posing a phishing attack risk

By: www.chaincatcher.com|2026/03/19 04:42:00

After Slow Mist founder Yu Xian disclosed that the Coinbase Commerce asset recovery page directly requires users to enter plaintext mnemonic phrases, Slow Mist's Chief Information Security Officer 23pds added that the sitemap of that page also has flaws, allowing malicious attackers to easily use tools like ResourcesSaver to download the frontend code and deploy similar websites.

If combined with similar domain names like Coinbase for phishing attacks, users can easily fall victim.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

GitHub updates security incident investigation: An employee's device was compromised, involving a contaminated VS Code extension

GitHub has updated the details of the investigation into the unauthorized access incident of its internal repositories: GitHub detected and contained an incident yesterday involving an employee's device being compromised, which involved a maliciously implanted VS Code extension. GitHub removed the m...

Echo Protocol confirms it has been attacked and suspends all cross-chain transactions

Echo Protocol announced that it is investigating a security incident affecting the Echo cross-chain bridge on Monad. During the investigation, all cross-chain transactions remain suspended.According to previous reports, market news indicated that Echo Protocol was hacked on Monad. The attacker minte...

Slow Fog CISO: Grok was alerted to an injection attack resulting in a $175,000 DRB anomaly transfer

The Chief Information Security Officer (CISO) of Slow Mist @23pds posted on the X platform revealing that X platform user Ilhamrfliansyh induced the AI model Grok to generate and publish abnormal content through a prompt injection attack, triggering erroneous on-chain fund operations.It is alleged t...

Slow Fog releases MistTrack Skills: introducing on-chain AML risk analysis capabilities for AI Agents

Slow Mist announces the launch of MistTrack Skills, aimed at providing on-chain address risk analysis and anti-money laundering (AML) detection capabilities for AI Agents. In the context of the rapid development of AI Agents and the Skills ecosystem, this tool helps Agents automatically complete add...

Report from MEXC Ventures: Multi-Asset Trading Increases in Asia

5 Bitcoin Supply Signals Behind BTC's Move Toward $80K

Bitcoin nears $80K as supply tightens. Explore 5 key BTC supply signals, from long-term holders and ETF inflows to corporate buying and trade settlement.
...
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com