An unrequested Coinbase code is a warning worth acting on

A Coinbase code you didn't ask for means someone entered a working password on your account.

Treat this as more urgent than the same message from a shopping app, for one reason: a crypto transfer that leaves your account cannot be reversed. There is no chargeback, no fraud department that can pull it back, and no bank in the middle. Everything below is ordered accordingly.

What to do

1. Change your password and move off SMS

Change the password at coinbase.com, typed directly. Then change your second factor from text messages to an authenticator app or, better, a hardware security key.

This matters more on an exchange than anywhere else. SMS codes can be intercepted through a SIM swap, and SIM swaps are aimed disproportionately at people known to hold crypto. A hardware key removes that path entirely.

2. Check your API keys

This is the step that gets missed. API keys grant programmatic access to an account and keep working after a password change. If an attacker had access at any point, a key with withdrawal permissions is how they retain it quietly.

Review every key in your settings. Delete anything you don't recognize or no longer use, and confirm that keys you do keep don't carry permissions they don't need.

3. Set up address allowlisting

Coinbase supports restricting withdrawals to a saved list of addresses. With it on, funds can only leave to destinations you approved in advance, and adding a new one takes a delay plus confirmation.

This is the single strongest control available on the account. Turn it on now rather than after something goes wrong.

4. Review devices, sessions, and account activity

End sessions you don't recognize, then read the account activity log. You're looking for logins from unfamiliar locations, changed settings, added payment methods, or withdrawal attempts, whether or not they succeeded.

5. Secure the email address on the account

An exchange account is only as safe as the inbox behind it. Change that password, put a strong second factor on it, and check for forwarding rules or filters you didn't create.

6. Consider moving long-term holdings off the exchange

If you're holding an amount you'd struggle to lose, an exchange account reachable with a password and a text message isn't the right place for it. A hardware wallet takes the account compromise question off the table for those funds.

Why you specifically

Part of this is automated. Attackers replay credentials leaked from unrelated breaches across major exchanges, and a hit on a funded account is worth far more than a hit on a retail login.

But crypto holders also get selected deliberately. Lists circulate. Someone who appears in a breach of a crypto-adjacent service, or who has posted publicly about holdings, becomes a candidate for the more expensive attacks, including SIM swaps and tailored phishing.

Making that targeting work requires knowing how to reach you. Data brokers and people-search sites publish current phone numbers, email addresses, and home addresses next to full names, assembled from public records and commercial data. That's the material behind a convincing "Coinbase security" call, and it's what a SIM swap attempt needs before it can start.

Delist finds those listings, files the removals, and keeps re-checking them, because brokers routinely repost profiles. Run a free scan to see what's currently published about you.

The broader pattern is covered in why you're suddenly getting 2FA codes you didn't request.

Frequently asked questions

Does an unrequested Coinbase code mean my funds are at risk?

It means someone has a working password and was stopped at the second step. Funds are not gone. Change the password, replace SMS with a hardware key or authenticator app, and turn on address allowlisting.

Someone called from Coinbase support about suspicious activity. Is that real?

No. Coinbase does not call customers to ask for codes, passwords, or seed phrases, and does not ask you to move funds to a "safe" wallet. That call is the attack. Hang up.

Can they withdraw crypto without the code?

Not through a new login. The realistic paths are an existing API key, a session that's already signed in, or convincing you to approve something yourself. Reviewing API keys closes the one people forget.

I use SMS 2FA. How exposed am I?

Enough that it's worth changing today. Crypto accounts are the primary target of SIM swap attacks, and an intercepted text defeats SMS-based protection completely.

What is address allowlisting and should I use it?

It restricts withdrawals to addresses you've pre-approved, with a delay before a new one becomes usable. Yes, use it. It's the control that limits damage even if someone gets fully in.

Find out what data brokers know about you

Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.

Start your free scan