At least as far as a whole system goes including the soft squishy components designing, developing and operating it.
Even for cryptography the only absolute proven secure method is the one time pad which has very real practical flaws and risks if you try to operate it in the real world.
The threat model here is people leaking their own Coinbase passwords (via phishing, compromised PC, etc.), so the 48-hour delay and out-of-band verification ought to actually help.