Coinbase Bug Bounty Volume Soars as AI-Generated Reports Flood In
Coinbase's bug bounty program is seeing a surge in reports, with volume on track to triple from last year. However, only 4% of first-half HackerOne reports were valid paid bugs. Human reviewers are facing a growing screening burden as inexpensive AI tools allow security researchers to scan software and produce vulnerability reports rapidly.
The rising volume coincided with a smaller share of credible discoveries, falling from 14% in 2024 to 4% during the first half of 2026. Coinbase associated researchers' growing AI use with a sharp increase in AI-generated reports but did not specify what percentage of total submissions involved automated tools.
Among HackerOne reports closed during the first half, 44% were duplicates, 37% contained information without an exploitable flaw, and 15% were invalid. External researchers Joe Almeida and Anh Nguyen discovered a subtle weakness involving Coinbase's reconciliation of Stellar withdrawals, which could have led to spending being counted twice internally.
Coinbase has narrowed its Web2 bug bounty program to high, critical, and extreme vulnerabilities, with rewards remaining unchanged at up to $1 million for extreme vulnerabilities. The company uses an external platform called HackerOne where independent researchers submit software vulnerabilities to companies for review and possible rewards.