Skip to content

Security guide

Coinbase Wallet extension security, in plain English

A wallet extension gives you complete control, which means it also gives you complete responsibility. Here is the practical version: what protects you, what the common attacks look like, and what to do the moment something goes wrong.

On this page

The short version

Keep the recovery phrase offline and private. Install only the genuine extension. Read every prompt before approving. Review approvals periodically. Use a separate wallet, ideally behind a hardware device, for anything you cannot afford to lose.

The self-custody model, and what it implies

In a self-custody wallet, the private key is generated on your device and stays there. Nobody at Coinbase — or anywhere else — can move your assets, freeze them, or restore them for you. That is the entire point, and it produces three consequences worth internalising.

What self-custody changes about help and recovery
SituationSelf-custody walletCustodial account
You lose your recovery phraseAccess is gone permanentlySupport can restore access
A scammer gets your signatureNo chargeback, no reversalSometimes reversible
Your country restricts a serviceYour keys still workThe provider can block you
You want a business to undo a mistakeImpossible by designOften possible

This is not a flaw to work around; it is the trade you are making. The practical response is not to fight it but to reduce the number of ways it can go wrong: fewer approvals, less exposure, better backups.

Recovery phrase rules

The recovery phrase — usually 12, sometimes 24 words — is the master key. Anyone who reads it can recreate your wallet on their own device and empty it, on every network, without your password. There is no partial theft and no time limit.

Do

  • Write it by hand, in order, on paper or a metal backup plate.
  • Store it offline, in one or two physically secure places.
  • Verify your written copy by restoring from it once, if you want certainty.
  • Keep it apart from your wallet password.

Never

  • Photograph it, scan it, or type it into a note, doc or chat.
  • Save it in a password manager's notes field or a cloud drive.
  • Read it aloud on a call, stream or video, or share it with family "just in case".
  • Enter it into a website, pop-up or "wallet validation" page.

The one question that ends every scam

If anyone — a person, a chat, a support desk, a form, a browser pop-up — asks for your recovery phrase or private key, the answer is no. Every legitimate service works without them, because no legitimate service needs them.

Related: if you have not set up a wallet yet, the backup step of the setup guide walks through this in order.

Device and browser hygiene

The extension is only as private as the computer it runs on. Most of what attackers actually exploit is the environment around the wallet: the clipboard, the screen, the browser profile, a browser extension you forgot about.

Lock the device

Disk encryption plus an auto-locking screen. An unlocked, unattended laptop is the simplest wallet attack there is.

Audit your extensions

A malicious extension can read page content, rewrite addresses or watch what you copy. Keep only what you can name and justify.

Beware clipboard hijackers

Some malware swaps a copied address for the attacker's. Always check the first and last characters before you send.

Use a dedicated browser profile

Do wallet work in a profile you visit nothing else with. Fewer cookies, fewer extensions, fewer chances.

Keep everything updated

Browser, operating system and wallet updates carry security fixes, not just features.

Assume public Wi-Fi is watched

Use your phone's hotspot for large transactions. HTTPS protects a lot, but not everything.

Spotting a fake extension or a fake store listing

Impostor extensions are the most direct route to wallet theft: the victim installs a look-alike, sets up a wallet inside it, and the phrase is quietly sent to the attacker. The imitation is often excellent, so verify rather than trust your eye.

  • Reach the store from an official page, not a search result, an ad, a video description or a message.
  • Publisher line first. The developer must be the real company — not a name with a hyphen, an extra word, or a letter swapped for a similar glyph.
  • Compare the update history. A brand-new listing for an established product is a contradiction.
  • Read the permission list. A wallet needs to interact with pages you visit. It has no business reading your downloads or controlling other extensions.
  • Never "fix" a wallet through a link someone sends you. Support does not arrive as a link, a form or a remote-access session.

If you already installed a suspicious extension

Remove it now, and treat every wallet whose recovery phrase was typed into it as compromised — the phrase leaves the wallet the moment it is entered. Create a new wallet with a new phrase and move funds out of the old one. See what to do if your wallet is compromised.

Phishing and social engineering

Most losses do not come from broken cryptography. They come from a person being persuaded to approve something. The standard plays are consistent enough to be recognised.

Common wallet phishing scenarios
The approachHow it worksYour move
A site that looks like a walletA near-identical domain asks you to "reconnect" or "validate" your wallet.Check the domain character by character. Real wallets never ask you to enter a recovery phrase on a website.
"Support" in a direct messageSomeone offers to fix your problem and asks for your phrase, a screen share, or a remote-access tool.Ignore and block. Official support does not start conversations with you and never needs your keys.
A giveaway or airdrop that needs a signatureSigning a malicious message grants permission to move your assets later.Decline. Free money that requires a signature is the oldest drainer in the book.
Urgency: "your wallet will be deactivated"Fear and time pressure stop you reading the prompt.Nothing legitimate expires in five minutes. Walk away and check the official domain.
A fake "unlimited approval" fixA tool promises to revoke approvals and instead requests new ones.Revoke through a reputable approval explorer or the wallet itself.

Approvals, signatures and standing permissions

There are three kinds of request, and confusing them is how people lose tokens without ever sending a transaction.

Connect

Reveals your public address. Low risk; disconnect any site you stop using.

Sign

Proves control of the address, or authorises a contract action. Read the text, not just the button.

Approve

Grants a contract permission to spend a token. This is the dangerous one.

  • Prefer a limited approval amount over an unlimited one when the interface offers it.
  • Revoke approvals you no longer need — a private key cannot be leaked through an old approval, but a contract bug can still be exploited through it.
  • Check the spender contract address against the project's official documentation.
  • Treat any prompt you do not understand as a refusal, and come back to it later.

Scam patterns worth recognising on sight

Address poisoning

A tiny transfer arrives from an address resembling one you have used, so a careless copy from history sends your next payment to the attacker.

Drainer sites

Wallets are emptied through a single signature or approval on a site that looked like the real project.

Fake tokens and NFTs

A surprise asset in your wallet is bait: interacting with the attached site is the trap.

Impersonated staff

Direct messages from "Coinbase security", with a badge image and a helpful tone, ending in a request for your phrase.

Remote-access requests

Any request to install a screen-sharing tool during "wallet recovery" is theft in progress.

Romance and investment cons

Weeks of trust-building, then a curated "platform" that is really a drainer with a login page.

A monthly safety checklist

  • Approvals: revoke anything attached to a project you no longer use.
  • Connected sites: disconnect everything you do not recognise.
  • Backup: confirm your written phrase is still legible and where you left it — and still strictly offline.
  • Extensions: remove anything you cannot justify, and check that the wallet and browser are up to date.
  • Balances: compare what the wallet shows against a block explorer for your main addresses, in case something moved without you.
  • Separate wallets: is your savings account still connected to nothing?

If your wallet is compromised

  1. 1

    Act first, investigate later

    If you believe your keys or a permission has been taken, create a brand-new wallet with a brand-new recovery phrase on a device you trust, and move whatever remains. Speed matters more than tidiness: a compromised key can be emptied at any moment.

  2. 2

    Do not keep using the old wallet

    Abandon it entirely. Adding funds back, or reusing the same phrase for a "new" wallet, hands everything you add to the attacker.

  3. 3

    Revoke and disconnect

    From the new wallet or an approval explorer, revoke the approvals held by the old address and disconnect every site. Do this even though the funds are gone — it stops anything sent there by mistake later from being swept.

  4. 4

    Check what else was exposed

    If the same phrase, password or email appeared anywhere else, rotate those credentials too.

  5. 5

    Report it, but manage expectations

    Report the site or the impostor extension to your browser's store and to Coinbase's official support channels so it can be taken down for the next person. Understand that an on-chain transaction cannot be reversed, and that anyone promising to recover funds for a fee is running a second scam.

Talking to official support

Always start from Coinbase's own help centre rather than a link you were given, and never grant remote access to your computer during a support conversation. Support will not ask for your recovery phrase, and no legitimate recovery service exists.

Independent, informational resource

This page is educational content about browser-based self-custody wallets. It is not affiliated with, endorsed by, sponsored by, or operated by Coinbase, and it is not an official download page. Company and product names are the trademarks of their respective owners and are used here only to describe the products being discussed. Always get wallet software from the official source, and never share your recovery phrase with anyone.