Coinbase Wallet extension security, explained

A self-custody wallet is about as safe as the person using it. This page separates what the software protects you from, what only your habits can protect you from, and how the common scams actually work.

Last reviewed: September 2026Security · threats, habits and recovery

What the extension protects you from

The extension is a local vault with a confirmation screen. That gives you three real protections:

  • Keys are encrypted and stay on your device. They are held behind the password you set and are not stored on a Coinbase server that could be breached or subpoenaed.
  • Nothing moves without your approval. A connected site can request a transaction; it cannot sign one. Every transfer, swap and approval opens a window that you accept or reject.
  • You see what you are signing. The confirmation shows the network, the amount, the contract and the destination. Most losses happen because that window was clicked through rather than read.

Wallets keep improving the warnings they show — flagged sites, risky approvals, transaction previews. Treat any warning you see as a signal to stop, and confirm the current protections on the official Coinbase Wallet page.

What is entirely on you

Self-custody moves four jobs from a company to a person. If any of them slip, the wallet's technology cannot save the funds:

  • The recovery phrase. Twelve words, kept offline, in more than one place. It is the only thing standing between a broken laptop and a lost balance.
  • The device. Malware that watches your screen or clipboard defeats a good wallet. Keep the operating system and browser updated, and keep the wallet on a machine you actually maintain.
  • What you approve. A signature is a legal-in-practice instruction to a contract. Approve a swap on a fake site and there is no reversal.
  • Where you install from. The browser cannot tell that a counterfeit extension is counterfeit. You are the control.

There is no recovery team

Coinbase cannot restore a self-custody wallet, freeze a transfer, or reverse a transaction. It also does not need your phrase for anything — so anyone who asks for it is a thief, whatever name they use.

Threat patterns

Scam patterns to recognise on sight

Counterfeit extension listings and adverts

Fake wallets are advertised above the real one in search engines and app stores, and they collect recovery phrases at setup. Install from a bookmark of the official page, and check the publisher and install count before you click Add.

“Connect” or “validate” phishing sites

A site that imitates a real service and asks you to connect a wallet, then asks you to “validate” or “sync” it by typing twelve words. No real service needs the words. Ever.

Fake support and DMs

Someone offers to help in a chat, a comment thread or an email, then asks for your phrase or a screen share “to check the settings”. Support staff never need either, and legitimate support does not start in a direct message.

Airdropped tokens and NFTs that point at a site

Anyone can send an asset to any address. Unexpected tokens and collectibles often carry a name or a URL urging you to visit and claim something — which is the trap. Leave them alone.

Approvals and signature requests

Unlimited token approvals, and signature prompts that look routine, can hand a contract lasting access to your balance. Read contracts and spend limits, reject what you did not initiate, and revoke old approvals periodically.

Address poisoning and clipboard malware

Attackers send dust from an address that mimics one you use, hoping you copy it from your history, and some malware swaps the address you copied. Check the first and last characters of any address before sending.

Routine

A safety checklist you can keep

Set-up habits

  • Install from a bookmark of the official page.
  • Write the phrase by hand; never photograph it or save it to a cloud note.
  • Store it in two places you control, and verify it once by reading it back.
  • Use a unique password — different from anything else you own.

Ongoing habits

  • Check the domain and the lock icon before connecting a wallet.
  • Read every confirmation window before approving.
  • Revoke approvals and disconnect sites you no longer use.
  • Keep a small working balance in the browser wallet and the rest elsewhere.
  • Attach a hardware wallet for amounts you cannot afford to lose.

If you think a wallet has been compromised

Speed matters, but so does order — moving funds with the same compromised browser or the same phrase makes things worse. Work in this sequence:

  1. 1

    Stop, and stop trusting that machine

    Do not keep approving things, and do not enter your recovery phrase anywhere while you are unsure. If malware is a possibility, do the next steps from a different device.

  2. 2

    Revoke approvals and disconnect sites

    Remove site connections in the wallet, and revoke token approvals using a reputable revoke tool from a trusted source. This closes doors that were already open.

  3. 3

    Create a fresh wallet with a brand-new phrase

    Generate a new wallet on a device you trust — do not reuse a phrase that may have been exposed, and do not send funds back to an address generated inside the wallet you no longer trust.

  4. 4

    Move what is left, then clean up

    Send remaining funds to the new wallet, then clean the device: uninstall unfamiliar extensions, scan for malware, and change the passwords that were typed on it.

Privacy: what is public and what is not

A wallet address is a public record. Anyone who learns it can see every balance and every transaction permanently, and analytics firms specialise in linking addresses to each other and to people. Self-custody protects your keys, not your privacy.

In the browser, an installed wallet needs to see the pages you visit in order to offer connections to them — that is the permission you approved during installation, and it is the reason you should not install a wallet you did not mean to install. This website runs no accounts and no analytics of its own; see the privacy page for the detail.

Security questions

What people ask about wallet safety

Is the Coinbase Wallet extension safe?

The extension itself is a legitimate, widely used wallet, but self-custody means the security decisions are yours. The two biggest risks are phishing — fake extension listings and lookalike websites that ask for your recovery phrase — and a compromised computer. Install only from the official source and treat your 12-word phrase like the key to a safe deposit box.

Why does the extension ask for permission to connect to a website?

Connecting a site shares your public wallet address and lets that site ask you to sign transactions. It never hands over your private keys, and every transaction still needs your approval. You can disconnect a site at any time from the wallet's connected-apps list.

Where is my recovery phrase stored?

Only on your device, encrypted behind the password you set, and anywhere you deliberately wrote it down. Coinbase does not keep a copy, so nobody at Coinbase can restore your wallet. If you lose the device and the phrase, the funds in that wallet are permanently unreachable.

Can I use a hardware wallet with it?

Coinbase Wallet supports connecting certain hardware wallets so that transaction approvals happen on the device rather than in the extension — the strongest setup if you hold larger amounts. Hardware support depends on the wallet model, so confirm current compatibility in the official documentation.

The phrase, restated

Twelve words written by hand on paper or metal, stored offline, never typed into a website. That single habit prevents most losses people report.

What good looks like

A small balance in the browser wallet, a hardware wallet for savings, approvals reviewed monthly, and no one — ever — being told the recovery phrase.

Educational information only. Nothing on this page is financial, tax or legal advice, and no wallet is risk-free — self-custody means accepting that a mistake can be permanent. For account-specific problems, use the official Coinbase Wallet help centre and be careful with anyone who contacts you first.