Guides

Unexpected Coinbase Device Confirmation Email? What to Do First

If Coinbase sends a device confirmation email you did not trigger, treat it as a real account-security event. Here is the safest order: lock the account, change passwords, review devices, and harden 2FA before you trade or withdraw again.

Published July 20, 2026Updated July 20, 2026

If Coinbase sends a device confirmation email that you did not trigger, do not treat it like a harmless glitch.

Coinbase says an unexpected device confirmation email means someone was able to use your password and 2-step verification code to begin signing in to your account. That does not always mean they finished getting in, but it is already serious enough to treat as an account-security event.

The right response is not panic-selling, clicking random support links, or rushing a withdrawal to whatever address feels convenient. The right response is to lock the account down in the correct order.

Short answer

If this happensBest next step
You got the email and you were not trying to sign inOpen Coinbase from your own bookmark or typed URL, not from the email
You still have access to your accountLock the account, change passwords, and review sessions and confirmed devices
You reused that password elsewhereChange the Coinbase password and the email-account password immediately
You only use SMS for 2FAUpgrade to a passkey, security key, or stronger 2FA method as soon as access is secured
Someone is calling or messaging you about the alertTreat it as a likely scam and use only official Coinbase channels

1. First, do not trust the situation just because the email mentions Coinbase

Coinbase documents real device confirmation emails, but it also warns that real Coinbase emails will never ask for your password, 2-step verification codes, or remote access to your computer.

That means two things can be true at once:

  1. the alert may describe a real sign-in attempt;
  2. scammers may also use the same situation to pressure you into a bad next step.

So do not click around in a panic.

Open Coinbase from your own bookmark or type coinbase.com yourself. If you want a broader scam checklist first, read Crypto Support Call Scam.

2. Lock the account before you start troubleshooting

Coinbase's compromised-account guidance says you can use Security Lock if you believe someone gained unauthorized access. While the account is locked, you can still sign in, review activity, and contact support, but trading, transfers, and account changes are paused.

That is exactly what you want early in the response.

A temporary pause is better than leaving the account open while you guess what happened.

If you can still reach the official Coinbase app or site safely, lock the account first. Coinbase says locking the account signs you out from all devices.

3. Change the Coinbase password and the email password

Coinbase says to change your Coinbase password immediately and use one that is entirely new, unique, and unrelated to old passwords.

Do not stop there.

Coinbase also tells users to change the password on the personal email account tied to Coinbase and add strong 2-step verification there too. That matters because email recovery is often the back door into an exchange account.

If the same password was ever reused on another site, assume the problem may be bigger than Coinbase alone.

4. Review active sessions and confirmed devices

Coinbase specifically tells users to review the account activity page, active sessions, and confirmed devices. If anything looks unfamiliar, revoke it by signing out the session or removing the confirmed device.

This step matters because the problem is not only "Did someone know my password?"

The problem is also:

  • did they create a live session?
  • did they confirm a device?
  • did they get far enough to make later account changes easier?

If you see unfamiliar activity, do not brush it off as a travel-VPN false alarm until you understand it.

5. Upgrade weak 2FA after the account is contained

Coinbase says SMS is the least secure 2-step verification method and recommends stronger methods such as a passkey or security key.

If an attacker got far enough to trigger an unexpected device confirmation email, this is the wrong time to keep a weak setup.

After you contain the account:

  • move away from SMS-only 2FA if possible;
  • add a stronger sign-in method such as a passkey or security key;
  • make sure you still have a safe backup way to recover access.

For the broader setup, use our crypto exchange account security checklist.

6. Check whether you typed your credentials into a fake site

Coinbase explicitly tells users to review browsing history and check whether they accessed a site impersonating coinbase.com.

That detail is easy to miss.

Sometimes the email is not the first attack. The first attack was the fake login page you used earlier.

If you think you may have entered credentials into an impostor site:

  • treat the password as stolen;
  • change it immediately from a clean session;
  • review devices and sessions again;
  • be extra careful about follow-up texts, calls, or emails claiming they can "help recover" the account.

Related reading: Fake Crypto Wallet Apps and How to Avoid Them and Common Crypto Scams and How to Avoid Them.

7. Do not rush a withdrawal just to feel in control

A common bad reaction is to try to move all funds instantly while stressed.

That can create a second problem:

  • sending to the wrong network;
  • using the wrong address;
  • trusting a fake support instruction;
  • disabling useful security friction in a hurry.

If you decide to withdraw after securing the account, use a controlled process. Verify the destination carefully, prefer an address you already trust, and send a test transaction first. If your long-term plan is self-custody, follow How to Move Crypto from an Exchange to a Hardware Wallet Safely.

8. When this is probably a real threat vs a normal re-confirmation

Coinbase also documents normal device re-confirmation events. You may need to confirm again after clearing cookies, using another browser, switching networks, or using a VPN.

That is different from an email you did not trigger.

Use this rule:

SituationTreat it as
You just tried to sign in on a new browser or devicePossibly normal device confirmation
You cleared cache, used incognito mode, changed networks, or used a VPNPossibly normal re-confirmation
You were not signing in at all and still got the emailA security event until proven otherwise
The email is followed by a call, text, or pressure to move fundsHigh scam risk

Who this guide is for

SituationBest takeaway
You received a Coinbase device confirmation email out of nowhereTreat it as a real compromise warning and secure the account in order
You are not sure whether the email was legitimateUse only your own bookmark or typed domain, not panic-clicking
You secured the account but still rely on SMSUpgrade to stronger 2FA now
You want an easier exchange-security baseline for the futureHarden the account before the next deposit

Bottom line

An unexpected Coinbase device confirmation email is not something to ignore.

Coinbase's own guidance says it means someone was able to use your password and 2-step verification code to begin signing in. The safest order is:

open Coinbase from your own trusted path, lock the account, change Coinbase and email passwords, remove unfamiliar sessions or devices, and upgrade weak 2FA before you trade or withdraw again.