Coinbase’s bug bounty measurement is connected way to triple arsenic AI-generated submissions flood its reappraisal queue, yet lone 4% of first-half HackerOne reports were valid paid bugs. Human reviewers indispensable abstracted credible threats from a increasing question of low-value reports.
Key Takeaways
- Report measurement remains connected gait to triple from past year.
- Only 4% of first-half reports submitted done Hackerone were valid paid bugs.
- Human researchers uncovered a Stellar flaw that AI missed.
Why Are Coinbase’s Bug Reports Surging?
Human reviewers look a increasing screening load arsenic inexpensive AI tools let information researchers to scan bundle and nutrient vulnerability reports rapidly. Crypto speech Coinbase (Nasdaq: COIN) outlined the inclination Aug. 11 successful its information disclosure, reporting that submissions are connected way to scope 3 times past year’s volume aft doubling the twelvemonth before.
The rising measurement coincided with a smaller stock of credible discoveries. Coinbase indicated that the valid-report stock fell from 14% successful 2024 to 4% during the archetypal fractional of 2026. The institution associated researchers’ increasing AI usage with a crisp summation successful AI-generated reports but did not specify what percent of full submissions progressive automated tools.
Coinbase narrowed its Web2 bug bounty program connected July 29 to high, critical, and utmost vulnerabilities. Among Hackerone reports closed during the archetypal half, 44% were duplicates, 37% contained accusation without an exploitable flaw, and 15% were invalid. Extreme vulnerabilities stay eligible for rewards of up to $1 million. Hackerone is an outer level wherever autarkic researchers taxable bundle vulnerabilities to companies for reappraisal and imaginable rewards. Coinbase uses the Web2 statement for accepted websites, applications, and supporting services. Its abstracted Cantina programme covers blockchain and smart-contract vulnerabilities.
What Did Human Researchers Find?
External researchers Joe Almeida and Anh Nguyen discovered a subtle weakness involving Coinbase’s reconciliation of Stellar withdrawals. Stellar’s fee-bump mechanism allows a 3rd enactment to wrapper an existing transaction and wage a higher web interest without requiring caller signatures oregon sequence-number management.
Coinbase’s strategy could dainty the archetypal transaction arsenic failed nether definite conditions adjacent aft the intended transportation succeeded onchain. That discrepancy created the imaginable for spending to beryllium counted doubly internally. Coinbase paused the affected process, confirmed a correction, and restored mean processing.
Customer funds remained unaffected, and Coinbase recovered nary grounds of exploitation beyond the researchers’ impervious of conception and interior testing. AI separately flagged a related, little terrible deposit-side defect. The findings exemplify Coinbase’s intended part betwixt automated screening and specializer investigations involving protocol rules and interior accounting.
A abstracted AI-assisted Bitcoin information audit produced 4,962 imaginable findings crossed 390 repositories during a 27.5-hour review. About one-fifth had been independently reproduced astatine publication, leaving quality confirmation indispensable earlier the remaining alerts could beryllium treated arsenic established vulnerabilities.
How Are Criminals Applying AI?
Attackers tin deploy the aforesaid exertion to accelerate phishing, impersonation, and credential theft. The Federal Bureau of Investigation warned that generative AI helps criminals nutrient convincing messages faster, automate operations, and grow their excavation of imaginable targets.
An Aug. 10 investigation of North Korea-linked Kimsuky enactment identified AI platforms and generated documents crossed associated infrastructure. Investigators observed phishing worldly aimed astatine virtual assets, fiscal investment, and bundle improvement targets.
A March 6 study connected the Tycoon 2FA phishing work described exertion that intercepted progressive sessions and captured tokens utilized to bypass multifactor authentication. A coordinated disruption removed 330 domains tied to the operation.
What Does the AI Security Shift Mean for Consumers?
For consumers, AI tin summation onslaught velocity and marque phishing messages much convincing, portion bug bounty measurement chiefly affects institution reappraisal teams. A July 30 onchain information appraisal counted 212 exploits and $1.1 cardinal successful losses during the archetypal fractional of 2026.
Individual precautions stay applicable portion exchanges grow automated reviews and clasp specialized researchers. Standard integer plus information practices see unafraid wallet backups, beardown password management, and two-factor authentication. Coinbase’s revised programme leaves Web3 rewards unchanged portion concentrating its nationalist Web2 bounty payments connected high-impact flaws.

1 day ago









English (US)