• News/
  • https://www.bleepingcomputer.com/news/security/coinbase-to-fix-2fa-account-activity-entry-freaking-out-users/

Coinbase to fix 2FA account activity entry freaking out users

BleepingComputer
·
Lawrence Abrams
·
Published Apr 5, 2025
·
Updated

Coinbase is fixing a misleading account activity message that has caused confusion and anxiety, making users think their credentials were compromised. Over the past couple of weeks, numerous people have contacted BleepingComputer about concerns that they think Coinbase has a serious security issue. After receiving Coinbase phishing emails or texts, they logged into their accounts and checked the activity log, finding numerous entries stating "second_factor_failure" or "2-step verification failed" with login attempts from unusual locations. Two-factor authentication prompts usually occur after a user successfully logs in with their credentials, so they immediately thought that their passwords were compromised and that only 2FA saved them from their account being hacked. This led them to change their passwords, check for malware, and grow anxious over what they believed was a breach. Making matters worse, these users claimed to have a complex, unique password at Coinbase, and there were no signs of malware on their devices, making them believe that Coinbase had been breached. However, it turns out that the "second_factor_failure" or "2-step verification failed" account activity messages are shown in two different scenarios—when a user incorrectly enters the wrong 2FA code or when someone tries to log into their account with the wrong password. BleepingComputer was able to confirm this by logging into someone's account with the wrong password and the person telling us that thei...

Read full article

Affected Software

2 affected components
Coinbase Coinbase
Coinbase Coinbase
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Coinbase addressing a misleading 2FA account activity message that has caused user confusion.

2

What security implications are discussed in the article?

The misleading 2FA message has led users to fear that their account credentials were compromised.

3

What products or software are affected?

The affected software is the Coinbase platform, specifically its two-factor authentication (2FA) feature.

4

How are users reacting to the misleading 2FA messages?

Users have reported feeling confused and anxious due to the misleading account activity notifications.

5

What action is Coinbase taking in response to the issue?

Coinbase is working to fix the misleading messages to alleviate user concerns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203