Coinbase Wallet Seed Phrase Lost Fresh_Supermarket

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search

Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Coinbase

Reddit user Fresh_Supermarket reports that they lost the seed phrase of their CoinBase Wallet and even though they had the wallet still running on their phone. There is no suggestion they were able to regain access to their funds. They lost $5,000.

About Fresh_Supermarket

Fresh_Supermarket started their sales career with a B2B sales internship[1][2]. After graduating from college[3] in May 2021[4][5], they spent a period of time working sales for Gartner[6], before moving into a full time sales development representative (SDR) role[2][7]. Their ultimate goal is to become an enterprise account executive[8].

About Coinbase Wallet

CoinBase Wallet describes itself as "Your key to the world of crypto"[9].

Store all of your crypto and NFTs in one place

Support for hundreds of thousands of tokens and dapps

Explore the decentralized web on your phone or browser

Protect your digital assets with industry-leading security


"its making me confirm transaction on old wallet account on the phone app.."

The Reality

Storing cryptocurrency requires a high degree of responsibility on the part of the holder. One of the primary responsibilities is to ensure that reliable backups are kept of all wallets. Typical wallet software will provide seed phrases for user convenience, which allow the wallet to regenerate private keys. Seed phrases need to be written down or engraved and stored securely. If this process is not completed when the wallet is set up, and something happens to the original wallet, then future access to the user's funds will not be possible.

What Happened

Reddit user Fresh_Supermarket reports that they had a CoinBase Wallet set up. It is unclear what backups were taken, if any[10][11]. What is clear is that they never backed up their 12 word seed phrase[10]. Their wallet was reported to have contained $5,000 USD[12], which is believed to be permanently lost.

Key Event Timeline - Coinbase Wallet Seed Phrase Lost Fresh_Supermarket
Date Event Description
December 18th, 2021 2:47:49 PM MST Reddit Post Created Reddit user Fresh_Supermarket creates a post to request help on Reddit[12].
December 18th, 2021 3:42:27 PM MST Confirmation Required After learning how to set up a new wallet, Fresh_Supermarket reports that they cannot transfer the funds from their old wallet to the new wallet because additional confirmation is needed[13][14].
December 18th, 2021 4:46:24 PM MST Made Some Form Of Backup Fresh_Supermarket reports that they made some form of backup prior to setting up the wallet, however it did not include the 12 word seed phrase[10].
December 18th, 2021 7:36:28 PM MST No Backup Confirmed Fresh_Supermarket states that they "don't have anything that's backed up"[11].

Total Amount Lost

The total amount lost has been estimated at $5,000 USD based on the initial report from Fresh_Supermarket[12].

Immediate Reactions

Fresh_Supermarket posted on Reddit for assistance and received some response from the community.

Post About Incident On Reddit

Fresh_Supermarket posted on Reddit for assistance[12]. They lost their Coinbase wallet seed phrase but still has access to the wallet through the Google Chrome extension. They seek advice on how to recover their funds, amounting to $5,000.

"I know... im dumb. So I got a new phone and lost my coinbase wallet seed phrase, however I still have coinbase wallet logged in on my Google Chrome extension. How do I get my money back? I have $5000."

Reddit Community Reactions

Reddit community members suggest creating a new wallet and transferring the funds, but the user encounters difficulties with the confirmation process on the old wallet app. They explore various options, including importing to MetaMask, but are unsure of the best course of action. Some members emphasize the importance of backing up the seed phrase in the future to avoid such issues[12][15][16][17][18].

Make a new wallet and tra[n]sfer.

Can't access your seed from chrome extension ? Look somewhere in settings

Tattoo the phrase on your body! Never lose it again!

Did you backup your old phone? That would be the only way to regain access. In the future write down your seed phrase and store it somewhere safe. Don't rely on being able to access it from your phone.

Ultimate Outcome

The exact outcome of this situation is uncertain. It is possible that all funds were permanently lost.

Total Amount Recovered

While the outcome is uncertain, there do not appear to have been any funds recovered in this case.

Ongoing Developments

It is unclear whether the wallet was recovered and any further actions that the Fresh_Supermarket may have taken following their Reddit post.

Individual Prevention Policies

Storing cryptocurrency requires a high degree of responsibility on the part of the holder. One of the primary responsibilities is to ensure that reliable backups are kept of all wallets. Typical wallet software will provide seed phrases for user convenience, which allow the wallet to regenerate private keys. Seed phrases need to be written down or engraved and stored securely. If this process is not completed when the wallet is set up, and something happens to the original wallet, then future access to the user's funds will not be possible.

Ensure that more than one copy of your seed phrase is kept, and that each copy is in a distinct location. For example, you may keep a backup copy in a bank vault. A common scheme is to split the 24 word seed phrase into 3 sets of 16 words each, such that any two of the sets are needed to unlock the wallet.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Many users may come from other backgrounds where funds are recoverable by a centralized service, which may be a suitable alternative for some users. Special education is required for all users who choose to interact at the blockchain level.

Never take for granted the limited knowledge of users of your service and their tendency to skip past provided information. It is recommended to design a simple tutorial and quiz for new users which explains the basics of seed phrases, strong password generation, secure two-factor authentication, common fraud schemes, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space. This tutorial and quiz should ensure their understanding and be a standard part of the sign-up or download process which is difficult or impossible to skip.

Having an insurance fund provides flexibility to assist users in the event that private keys are permanently lost, which would typically not be covered by any other available insurance product. Even if such a product existed, it would be unlikely that all users would use it. While the industry insurance fund is discretionary and the amount of assistance would be up to the community, it can cover all events, including user error.

Work with other industry platforms to set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

Many users may come from other backgrounds where funds are recoverable by a centralized service, which may be a suitable alternative for some users. Special education is required for all users who choose to interact at the blockchain level.

Create a standard tutorial and quiz for all new cryptocurrency participants, which is required to be completed once per participant. This tutorial and quiz should cover the basics of proper seed phrase protection, strong password generation, secure two-factor authentication, common fraud schemes, how to detect and guard against phishing attacks, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space.

Having an insurance fund provides flexibility to assist users in the event that private keys are permanently lost, which would typically not be covered by any other available insurance product. Even if such a product existed, it would be unlikely that all users would use it. While the industry insurance fund is discretionary and the amount of assistance would be up to the community, it can cover all events, including user error.

Set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services within the country, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. Fresh_Supermarket - "just pick up any b2b sales internship and move into software sales full time post grad" - Reddit (Apr 5, 2023)
  2. 2.0 2.1 Fresh_Supermarket - "get any b2b sales internship before your senior year" - Reddit (Apr 5, 2023)
  3. Fresh_Supermarket - "I'm a college graduate as well." - Reddit (Apr 5, 2023)
  4. Fresh_Supermarket - "graduating next may" - Reddit (Apr 5, 2023)
  5. Fresh_Supermarket - "Seems like we are on a similar boat." - Reddit (Apr 5, 2023)
  6. Fresh_Supermarket - "the most I had was 4 and that was for Gartner" - Reddit (Apr 5, 2023)
  7. Fresh_Supermarket - "Currently deciding between starting my sdr career at mid stage startups or larger firms" - Reddit (Apr 5, 2023)
  8. Fresh_Supermarket - "my goal is to be an enterprise AE" - Reddit (Apr 5, 2023)
  9. Coinbase Wallet - Your key to the world of crypto (Mar 24, 2023)
  10. 10.0 10.1 10.2 Fresh_Supermarket - "I did back everything up but the 12 word seed phrase did not back up" - Reddit (Apr 5, 2023)
  11. 11.0 11.1 Fresh_Supermarket - "I don’t have anything that’s backed up" - Reddit (Apr 5, 2023)
  12. 12.0 12.1 12.2 12.3 12.4 Fresh_Supermarket - "Lost Coinbase Wallet Seed Phrase, but I still have access to the Wallet Chrome Extension" - Reddit (Mar 24, 2023)
  13. Fresh_Supermarket - "when i tried to send out from chrome extension, its making me confirm on the old wallet app" - Reddit (Apr 5, 2023)
  14. Fresh_Supermarket - "It is possible, but its making me confirm transaction on old wallet account on the phone app" - Reddit (Apr 5, 2023)
  15. Kiwip0rn - "Make a new wallet and tra[n]sfer." - Reddit (Sep 5, 2023)
  16. genesis_crazy_one - "Can't access your seed from chrome extension ? Look somewhere in settings" - Reddit (Sep 5, 2023)
  17. Rbwiseman - "Tattoo the phrase on your body! Never lose it again!" - Reddit (Sep 5, 2023)
  18. PsLJdogg - "Did you backup your old phone? That would be the only way to regain access. In the future write down your seed phrase and store it somewhere safe. Don't rely on being able to access it from your phone." - Reddit (Sep 5, 2023)