From a business point of view it's more like...who the f*ck cares what you use? Did they read it? Yes? Good, move on.
Usually companies use blogs as marketing tools to drive traffic to their websites. I might be wrong, but in the case of Coinbase I have never really seen anything they wrote that was precisely intended at selling a product. It's usually more informative, and shows they are trying to be more of a positive force in the industry compared to a dominant one. Kudos on them if it is the intent, and I guess it would explain the choice of platform instead of investing time and assets in developing their own.
Also, the customer is the PR/marketing department, not the engineering department. The marketing people already know how to use these platforms well, so just let them use those.
Look at the dns entries for lots of big company's blogs. Many of them are just CNAMEs for wpengine or some other third party host.
If they have a wordpress blog at blog.coinbase.com, then any xss attack in wordpress can steal customer accounts.
Sure, it's a fixable problem (by moving high security cookies into login.coinbase.com or something similar), but that's a big migration, and probably nowhere near the top of the engineering priority list.
I highly doubt either WordPress or Medium are susceptible to an XSS attack, but if I had to bet on one being safer I would bet on the open source software already used to power thousands of high profile websites.
I kinda wonder about that. I've been INUNDATED by Coinbase advertisements on mobile apps and etc talking about incentives for learning what they do and etc.
They seem to really be pushing to get the general public on board.
the opportunity cost is too high.
1. Allocation of engineering effort
2. Familiarity with readers
3. Discoverability
Which, honestly, is frequently deployed so poorly that it becomes an attack vector.