
Coinbase has resolved a confusing error in its account activity logs that caused unnecessary concern among users who feared their accounts had been compromised. The cryptocurrency platform was incorrectly labeling failed login attempts as two-factor authentication (2FA) failures rather than password errors.
When unauthorized login attempts occurred with incorrect passwords, users would see error messages like “second_factor_failure” or “2-step verification failed” in their account logs. These messages incorrectly suggested that attackers had successfully entered the correct password but were stopped at the 2FA verification step.
This mislabeling led many Coinbase users to believe their unique passwords had been compromised, despite having no malware on their devices and no other accounts being affected. The misleading logs prompted users to reset all their passwords and spend hours investigating potential security breaches.
Coinbase has now updated its system to correctly label these incidents as “Password attempt failed” in the Account Activity logs, providing users with accurate information about login attempts.
The bug was particularly concerning because such mislabeled entries could potentially be exploited in social engineering attacks. Threat actors frequently target Coinbase customers through SMS phishing and voice calls impersonating the company in attempts to steal credentials or 2FA tokens.
Coinbase reminds users that they never contact customers requesting password changes or 2FA resets, and all such communications should be treated as scams.
