Slowmist CISO: Coinbase Commerce Asset Recovery Page Sitemap Also Has Vulnerabilities with Phishing Attack Risks

ChainCatcher reports that after the founder of SlowMist, Yu Xian, disclosed the risk of directly asking users to input plaintext seed phrases on the Coinbase Commerce asset recovery page, SlowMist’s Chief Information Security Officer 23pds added that the site’s sitemap also has vulnerabilities. Malicious attackers can easily use tools like ResourcesSaver to download the frontend code and deploy similar websites.

If combined with similar domains like Coinbase for phishing attacks, users can be easily deceived.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin