Coinbase Unveils Continuous Adversarial Testing Platform for Enhanced Security
Consumer protection and security are top priorities for any financial institution, including cryptocurrency exchanges. In this regard, Coinbase has developed an internal platform called Continuous Adversarial Testing (CAT) to continuously test its assets and services for potential vulnerabilities.
CAT uses autonomous AI security agents that evaluate new activity in real-time while also testing existing assets as needed. This comprehensive approach covers web and mobile applications, backend services and infrastructure, Web2-to-smart-contract integrations, and internal AI tooling.
The platform's capabilities include new code scanning, PR security review, attack surface monitoring, existing code scanning, SAST & design hunts, Web2 ↔ Web3 connections, SHADE (Swarm Harness for Adversarial Discovery and Exploitation), MCP Registry Scanner, Prompt Injection Review, Agent skill trust, MAST (Continuous iOS/Android assessment), Dynamic testing, Infrastructure Testing, DAST (Agentic web-app testing), Live Operative, and Guardrails the Model Cannot Talk its Way Past.
The CAT platform has a multi-stage validation pipeline to ensure that every finding is thoroughly reviewed and verified before it reaches human eyes. This includes preflight checks, AI agent review, code-level tracing, and adversarial passes to confirm the validity of potential vulnerabilities.