It's ok, the coin will only connect to websites over an ethernet connection, and will only load a particular site if it can validate the full certificate chain.
A sufficiently crafted coin would be an interesting attack vector against a vending machine, for example. I'm interested to see how counterfeiters would be able to use a passive/active security device within the coin for potential gain.