A Coinbase Commerce subdomain has raised security concerns after reportedly directing users to a withdrawal page that requested their seed phrases. This practice, flagged by blockchain security expert Yu Xian, has been criticized for potentially normalizing behavior exploited in phishing scams. Coinbase has acknowledged the issue and is investigating, but has not yet provided further details. The page, referenced in a now-removed Coinbase Help guide, suggested users could recover funds by importing their seed phrases into wallets like Coinbase Wallet or MetaMask. Security researchers warn that such requests could be exploited by threat actors for social engineering attacks. Coinbase advises users against entering seed phrases on any website and has reiterated that it does not have access to users' seed phrases.