Coinbase fixes 2FA log error making people think they were hacked

Date:

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

As BleepingComputer first reported earlier this month, Coinbase had mistakenly labeled failed login attempts with incorrect passwords as two-factor authentication failues in the Account Activity logs.

When a threat actor attempted to access someone’s account and used the wrong password, error messages stating “second_factor_failure” or “2-step verification failed” would be shown instead.

These entries imply that a valid username and password were entered, but the log in was blocked by 2-factor authentication, such as entering the wrong one-time passcode from an authenticator app.

Numerous Coinbase users contacted BleepingComputer with concerns that Coinbase had been breached as their passwords were unique to the site, there was no sign of malware, and no other accounts were affected.

Incorrect 2FA error message in Coinbase Account Activity logs
Incorrect…

Read more…

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

Tampa RV giant Lazydays to delist from Nasdaq

Tampa-based Lazydays Holdings Inc., one of Florida’s most recognized...

Granite Geek: New Hampshire might get access to ‘balcony solar’

I had solar panels put on my roof six...

TSX Today: What to Watch for in Stocks on Monday, November 10

Despite firm gold and silver prices, Canadian stocks...

While BNB and DOT Struggle Under Market Pressure, BlockDAG’s Presale Soars Past $435M!

As market-wide fear grips the sector, the Binance Coin...