Gate News reports that on March 19, a subdomain page of a certain CEX Commerce displayed a prompt for users to input their wallet seed phrases, attracting the attention of security researchers. SlowMist’s Yu Xian stated that they cannot understand why the exchange would set up such a page, which directly asks users to enter seed phrases in plain text for asset recovery, considering it a serious security risk. On-chain analyst ZachXBT pointed out that this page was once referenced in a help document for a CEX Commerce product, which advised users to recover funds by importing seed phrases into a compatible wallet such as CEX Wallet or MetaMask, with a link to the withdrawal tool on that subdomain. The help document has since been removed. ZachXBT also noted that if malicious actors exploit this page, it could facilitate social engineering attacks on the exchange’s users.