Exchange safety

How to spot fake Coinbase emails

An email lands: “Your Coinbase account is at risk — verify now.” It looks perfect: right logo, right tone, a login button. The button doesn't go to coinbase.com — it goes to a copy built to capture your password and 2FA. This is the most common way Coinbase users lose funds.

How fake Coinbase emails work

Phishing emails create urgency (“account locked”, “suspicious login”, “withdrawal request”) and push you to a fake login page. The page forwards whatever you type — including your 2FA code — to the attacker in real time.

Signs an email is not really from Coinbase

A link that doesn't point exactly to coinbase.com; urgency and threats; requests for your password, seed phrase or 2FA; small misspellings in the sender domain.

What to do instead

  • Never click login links in emails. Open Coinbase from your own bookmark of coinbase.com.
  • Coinbase will never ask for your seed phrase — no real exchange ever does.
  • Enable an authenticator app or hardware key, not SMS, for 2FA.
  • Use a browser extension that blocks fake Coinbase login pages before they load.

Trust Line blocks fake Coinbase pages

Even if you click a link, Trust Line recognises look-alike Coinbase domains and stops the page loading — so a stolen click doesn't become a stolen account.

FAQ

Does Coinbase send emails asking me to log in?

Coinbase may send notifications, but you should never log in via an email link. Always open coinbase.com from a bookmark instead.

Will Coinbase ever ask for my seed phrase?

No. No legitimate exchange asks for your seed phrase. Any message that does is a scam.

設計段階からのプライバシー

Trust Line is a free browser extension that blocks fake versions of sites like this before they load and warns you about dangerous signatures on any site.

ブラウザに追加 — 無料