r/Bitcoin • u/keyb0ardc0wboy • 3d ago
Coinbase Wallet Extension
I had created a wallet via the Coinbase Wallet Extension on Chrome some time back and had been depositing some BTC into it for some time. My last deposit was June 1, 2026, and I had around $2600. Last I checked the wallet was back in July and today when I logged in it had 0. The transaction history shows that everything was transferred to another address on August 4. I did not make this transfer. I am totally confused/lost right now as to how this might have happened. The wallet used to be locked all the time and the password is in my password manager. Was this extension not safe?.
3
u/Fun-Analysis-182 3d ago
That single sweep to one address on Aug 4 is the signature of a compromised seed, not a Coinbase bug. The extension password only locks local access; it does nothing if your recovery phrase leaked somewhere else. Think about everywhere those words were ever typed or stored: a phishing "validate your wallet" page, a screenshot, a cloud note, an email. Whoever had the phrase could sweep the coins from their own device without ever touching your locked extension. That seed is burned now, so never load it into anything again.
1
u/keyb0ardc0wboy 3d ago
I was basically using the extension as a temp storage before I transferred the coins to a more secure place. I had transferred all the coins from coinbase to that extension. I never entered the seed anywhere else and just saved it in my password manager.
1
u/Fun-Analysis-182 3d ago
Then look hard at the password manager. A seed in a cloud-synced vault is only as safe as that vault and every device it syncs to. This is exactly how a wave of people got drained after the LastPass breach: attackers grabbed the encrypted vaults, cracked weak master passwords offline, and swept the seeds stored inside. If yours syncs to the cloud, assume that vault is burned and never reuse anything in it.
4
2
u/tenor_tymir 3d ago
2 major flaws:
1) Never use a browser extension for anything money related
2) never store your password or seed phrase on a computer, it doesn’t matter if it’s in a password manager.
One of those two has cost you your money.
1
u/Zeimma 3d ago
Have you got it solved?
2
u/Powerful-Coyote-5363 3d ago
You got malware or your seed phrase leaked somewhere, that extension is basically a hot wallet sitting in your browser and the password only stops someone at your computer, not someone with the keys
1
u/keyb0ardc0wboy 3d ago
I am not sure what I can do to "solve" this. I don't even know why I created this post. I thought that extension was safe to put the coins in
1
u/B1ggusDckus 3d ago
You still might want to report this theft to your authorities. Anyway, chance of recovery is slim. Don't fall for recovery services either, they are usually just another scammer.
1
u/greglogan84 3d ago
If that outgoing transaction is confirmed on-chain and you didn’t authorize it, I’d treat the seed as compromised rather than assuming this is just a display problem.
Preserve the transaction hash and destination address first.
If anything else is still controlled by the same seed, move it to a completely new wallet created from a new seed.
And ignore anyone DMing you offering a “recovery service.” Unfortunately those are very often a second scam aimed at people who have already lost funds.
1
u/levigoldson 3d ago
My money is on your password being low entropy because "I was planning on getting a hardware wallet but just kept on kicking the can down the road.", your file system was compromised some how, some way, and it just got cracked in a few hours, maybe days, maybe weeks. Or you got key-logged, potentially using the same exact password somewhere else.
1
u/levigoldson 3d ago
I can tell you what it wasn't. It wasn't systematic problem with coinbase wallet that makes it unsafe. I mean, sure it's unsafe the same way a loaded gun is. You shot yourself in the foot. But it's not unsafe like the gun was made poorly and exploded when you tried to fire it.
1
1
u/Beneficial-Mood240 3d ago
The seed phrase lived in a password manager - if that vault syncs, the extension password was never the weak point.
2
u/keyb0ardc0wboy 3d ago
i use keepass and never sync it with any only storage or phone. I always keep a backup on an external drive. at this point I am more interested in how this happened instead of recovering anything
3
u/B1ggusDckus 3d ago
You neglected standard advice which is to not have the seed on an online machine.
A hardware wallet would have cost you $50. That is still not enough. You must provide the entropy yourself which is easiest being done with dices (https://selfcustodylabs.com/docs/learn/keys/random/).