That terrifying "Coinbase Alert" buzzing on your phone? It might be a scammer with their fingers already on your retirement fund. Fake SMS phishing attacks impersonating Coinbase have exploded across 2024 and 2025, draining wallets in minutes. Here's how to fight back before you become the next victim.
What Is the Coinbase Text Scam?
The Coinbase text scam is a form of smishing — SMS phishing — where criminals impersonate Coinbase support or security teams through text messages. The messages often look nearly identical to legitimate Coinbase alerts, complete with branded language, shortened links, and a sense of urgency designed to make you panic.
Unlike old-school email scams, these attacks land directly on your phone, where guardrails are lower and people tap links reflexively. Scammers know that crypto investors check their phones constantly, and they exploit that muscle memory. The result: a wave of compromised accounts, emptied balances, and irreversibly lost funds.
Coinbase itself has repeatedly warned users that it will never ask for passwords, two-factor codes, or seed phrases via text. If you receive a message claiming otherwise, you are looking at a scam — full stop.
How the Scam Actually Works
Most Coinbase text scams follow a predictable playbook. You receive an SMS that looks something like:
Coinbase Security: Unusual login detected on your account. Verify your identity immediately: https://cbn-secure-verify.com
The link leads to a cloned login page — a pixel-perfect replica of Coinbase.com designed to harvest your credentials. Once you type your email and password, the fake site prompts you for your two-factor authentication code. That second code is the kill shot: it lets the attacker log in in real time, often from overseas, before you can react.
Some variants are more sophisticated. Scammers may already have your email from previous data breaches and use it to make the message feel personal. Others pose as "transaction confirmations" for withdrawals you never made, hoping you'll panic and call a fake support number. That phone line is staffed by smooth-talking operators trained to extract verification codes and seed phrases.
A newer twist involves SIM swapping. Attackers convince your mobile carrier to transfer your number to their SIM, intercepting legitimate Coinbase 2FA codes sent via SMS. Once they control your number, they can reset passwords and drain accounts without you ever clicking anything.
Red Flags That Scream "Phishing"
Spotting a fake Coinbase text is easier when you know what to look for. Watch for these warning signs:
- Suspicious sender IDs — Real Coinbase alerts come from a short code or the word "Coinbase." Scammers use random numbers or lookalike handles.
- Strange URLs — Long-press any link before tapping. Legitimate ones end in coinbase.com. Anything else (coinbase-secure, cb-verify, coinbase-help) is fake.
- Urgency and fear — "Your account will be locked in 24 hours!" Scammers want you to act before you think.
- Requests for sensitive info — Coinbase will never text you asking for passwords, 2FA codes, or seed phrases. Period.
- Spelling and grammar errors — Even polished scams slip up. Watch for odd phrasing or unusual punctuation.
- Unexpected 2FA codes — If you receive a verification code you didn't request, a scammer may already be trying to log in to your account.
When in doubt, don't click the link in the text. Open the Coinbase app or type coinbase.com directly into your browser to check your account status. That's the single safest habit you can build.
What to Do If You Already Clicked
Caught the scam too late? Move fast — every second counts. Here's your damage-control playbook:
Step 1: Lock Down Your Account
Log in to the real Coinbase site or app immediately and change your password. Then revoke all active sessions under Settings > Security and disable any API keys you don't recognize. If you can't log in because the attacker changed your password, use Coinbase's account recovery flow right away.
Step 2: Kill SMS-Based 2FA and Re-Enable It Safely
If you handed over a 2FA code, the attacker may still have a window. Remove SMS-based 2FA and switch to an authenticator app like Google Authenticator or, better yet, a hardware security key. Hardware keys are phishing-resistant and immune to most remote attacks.
Step 3: Contact Your Mobile Carrier
If you suspect a SIM swap, call your carrier from a different phone and ask them to lock your number with a port-protection PIN. This stops the attacker from receiving future SMS codes meant for you.
Step 4: Report the Scam
Forward the suspicious text to Coinbase's phishing-reporting address and file a complaint with the FTC at ReportFraud.ftc.gov. You should also report the number to your carrier by forwarding the message to 7726 (SPAM). The more reports, the faster carriers can shut these campaigns down.
Step 5: Monitor and Move Funds
If you hold significant balances, consider moving them to a self-custody hardware wallet while you sort things out. Coinbase cannot reverse crypto transactions, so prevention is everything.
Key Takeaways
The Coinbase text scam is one of the fastest-growing crypto threats of the year, but it preys on panic, not technology. Slow down, verify every link, and never share your 2FA code with anyone — not even someone claiming to be from Coinbase support.
Build your defenses now: enable an authenticator app or hardware key, lock your mobile number with your carrier, and bookmark the real Coinbase URL. A 30-second pause before tapping can save you from a five-figure loss.
And remember — in crypto, you are your own bank. Scammers aren't hacking computers anymore; they're hacking humans. Stay sharp, stay skeptical, and keep your seed phrase off your phone forever.
Zyra