Coinbase Cuts Rewards Amid Surge in Low-Value Bug Bounty Submissions
The Coinbase exchange has been hit by a surge in low-value bug bounty submissions due to advancements in artificial intelligence (AI) and automated tools. According to the company, AI-powered systems have become increasingly adept at identifying basic security vulnerabilities.
In response, the Coinbase has significantly altered its public bug bounty program on HackerOne's platform. The changes aim to discourage low-quality submissions by eliminating rewards for lower- and mid-severity vulnerabilities. For high-severity bugs, the maximum payout was reduced from $15,000 to $6,000, a 60% cut. For critical vulnerabilities, the maximum reward dropped from $50,000 to $15,000, a 70% decrease.
The Coinbase attributes this change to the increasing prevalence of automated tools and AI in bug bounty submissions. The company notes that its own internal systems are now capable of identifying many basic security issues, making it less reliant on external researchers for these types of discoveries.