Coinbase Commerce 页面要求用户输入助记词,引发安全隐患

链捕手
Yesterday

ChainCatcher 消息,据 Cointelegraph 报道,Coinbase Commerce 的一个子域名页面出现提示用户输入钱包助记词的操作流程,引发安全研究人员关注。SlowMist 余弦表示,无法理解 Coinbase 为何设置此类页面,直接要求用户以明文形式输入助记词进行资产恢复,认为此举存在严重安全隐患。

链上分析师 ZachXBT 指出,该页面曾被 Coinbase 的一篇 Commerce 产品帮助文档引用,文档建议用户通过导入助记词至 Coinbase Wallet 或 MetaMask 等兼容钱包来恢复资金,并附有指向该子域名提款工具的链接。目前该帮助文档已显示被删除。ZachXBT 同时指出,该页面若被恶意行为者利用,可对 Coinbase 用户实施助记词社会工程攻击。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10