Unexpected Coinbase Device Confirmation Email? What to Do First
If Coinbase sends a device confirmation email you did not trigger, treat it as a real account-security event. Here is the safest order: lock the account, change passwords, review devices, and harden 2FA before you trade or withdraw again.
If Coinbase sends a device confirmation email that you did not trigger, do not treat it like a harmless glitch.
Coinbase says an unexpected device confirmation email means someone was able to use your password and 2-step verification code to begin signing in to your account. That does not always mean they finished getting in, but it is already serious enough to treat as an account-security event.
The right response is not panic-selling, clicking random support links, or rushing a withdrawal to whatever address feels convenient. The right response is to lock the account down in the correct order.
Short answer
| If this happens | Best next step |
|---|---|
| You got the email and you were not trying to sign in | Open Coinbase from your own bookmark or typed URL, not from the email |
| You still have access to your account | Lock the account, change passwords, and review sessions and confirmed devices |
| You reused that password elsewhere | Change the Coinbase password and the email-account password immediately |
| You only use SMS for 2FA | Upgrade to a passkey, security key, or stronger 2FA method as soon as access is secured |
| Someone is calling or messaging you about the alert | Treat it as a likely scam and use only official Coinbase channels |
1. First, do not trust the situation just because the email mentions Coinbase
Coinbase documents real device confirmation emails, but it also warns that real Coinbase emails will never ask for your password, 2-step verification codes, or remote access to your computer.
That means two things can be true at once:
- the alert may describe a real sign-in attempt;
- scammers may also use the same situation to pressure you into a bad next step.
So do not click around in a panic.
Open Coinbase from your own bookmark or type coinbase.com yourself. If you want a broader scam checklist first, read Crypto Support Call Scam.
2. Lock the account before you start troubleshooting
Coinbase's compromised-account guidance says you can use Security Lock if you believe someone gained unauthorized access. While the account is locked, you can still sign in, review activity, and contact support, but trading, transfers, and account changes are paused.
That is exactly what you want early in the response.
A temporary pause is better than leaving the account open while you guess what happened.
If you can still reach the official Coinbase app or site safely, lock the account first. Coinbase says locking the account signs you out from all devices.
3. Change the Coinbase password and the email password
Coinbase says to change your Coinbase password immediately and use one that is entirely new, unique, and unrelated to old passwords.
Do not stop there.
Coinbase also tells users to change the password on the personal email account tied to Coinbase and add strong 2-step verification there too. That matters because email recovery is often the back door into an exchange account.
If the same password was ever reused on another site, assume the problem may be bigger than Coinbase alone.
4. Review active sessions and confirmed devices
Coinbase specifically tells users to review the account activity page, active sessions, and confirmed devices. If anything looks unfamiliar, revoke it by signing out the session or removing the confirmed device.
This step matters because the problem is not only "Did someone know my password?"
The problem is also:
- did they create a live session?
- did they confirm a device?
- did they get far enough to make later account changes easier?
If you see unfamiliar activity, do not brush it off as a travel-VPN false alarm until you understand it.
5. Upgrade weak 2FA after the account is contained
Coinbase says SMS is the least secure 2-step verification method and recommends stronger methods such as a passkey or security key.
If an attacker got far enough to trigger an unexpected device confirmation email, this is the wrong time to keep a weak setup.
After you contain the account:
- move away from SMS-only 2FA if possible;
- add a stronger sign-in method such as a passkey or security key;
- make sure you still have a safe backup way to recover access.
For the broader setup, use our crypto exchange account security checklist.
6. Check whether you typed your credentials into a fake site
Coinbase explicitly tells users to review browsing history and check whether they accessed a site impersonating coinbase.com.
That detail is easy to miss.
Sometimes the email is not the first attack. The first attack was the fake login page you used earlier.
If you think you may have entered credentials into an impostor site:
- treat the password as stolen;
- change it immediately from a clean session;
- review devices and sessions again;
- be extra careful about follow-up texts, calls, or emails claiming they can "help recover" the account.
Related reading: Fake Crypto Wallet Apps and How to Avoid Them and Common Crypto Scams and How to Avoid Them.
7. Do not rush a withdrawal just to feel in control
A common bad reaction is to try to move all funds instantly while stressed.
That can create a second problem:
- sending to the wrong network;
- using the wrong address;
- trusting a fake support instruction;
- disabling useful security friction in a hurry.
If you decide to withdraw after securing the account, use a controlled process. Verify the destination carefully, prefer an address you already trust, and send a test transaction first. If your long-term plan is self-custody, follow How to Move Crypto from an Exchange to a Hardware Wallet Safely.
8. When this is probably a real threat vs a normal re-confirmation
Coinbase also documents normal device re-confirmation events. You may need to confirm again after clearing cookies, using another browser, switching networks, or using a VPN.
That is different from an email you did not trigger.
Use this rule:
| Situation | Treat it as |
|---|---|
| You just tried to sign in on a new browser or device | Possibly normal device confirmation |
| You cleared cache, used incognito mode, changed networks, or used a VPN | Possibly normal re-confirmation |
| You were not signing in at all and still got the email | A security event until proven otherwise |
| The email is followed by a call, text, or pressure to move funds | High scam risk |
Who this guide is for
| Situation | Best takeaway |
|---|---|
| You received a Coinbase device confirmation email out of nowhere | Treat it as a real compromise warning and secure the account in order |
| You are not sure whether the email was legitimate | Use only your own bookmark or typed domain, not panic-clicking |
| You secured the account but still rely on SMS | Upgrade to stronger 2FA now |
| You want an easier exchange-security baseline for the future | Harden the account before the next deposit |
Bottom line
An unexpected Coinbase device confirmation email is not something to ignore.
Coinbase's own guidance says it means someone was able to use your password and 2-step verification code to begin signing in. The safest order is:
open Coinbase from your own trusted path, lock the account, change Coinbase and email passwords, remove unfamiliar sessions or devices, and upgrade weak 2FA before you trade or withdraw again.