BNB $608.88 -0.81%
XRP $1.01 -1.57%
ETH $1,880.63 -1.56%
BTC $63,411.92 -1.10%
BNB $608.88 -0.81%
XRP $1.01 -1.57%
ETH $1,880.63 -1.56%
BTC $63,411.92 -1.10%
BREAKING
Crypto Exchanges

Coinbase Bug Reports Set to Triple in 2026 as AI Floods HackerOne Queue

Coinbase Bug Reports Set to Triple in 2026 as AI Floods HackerOne Queue
Coinbase Bug Reports Set to Triple in 2026 as AI Floods HackerOne Queue

Community Trust ScoreVerified

85%
Real
Verified26 votes
Updated 1 hour ago

Coinbase is drowning in junk. The crypto exchange said bug bounty submissions are on pace to triple in 2026 compared to the prior year, and the culprit is pretty much what you’d expect: cheap AI tools that let anyone fire off hundreds of automated security reports with minimal effort.

The numbers are rough. During the first half of 2026, only 4% of reports submitted through HackerOne were deemed valid and actually paid out. That’s a brutal drop from 14% in 2024 — and the volume of submissions had already doubled in that same window. So more noise, far less signal. Coinbase didn’t say exactly how many of those reports were AI-generated, but the pattern is clear enough.

Of the HackerOne reports closed in the first half of the year, 44% were duplicates. Another 37% contained information that wasn’t exploitable. And 15% were just flat-out invalid. That leaves human reviewers wading through a pile of mostly useless submissions to find the few that actually matter.

Advertisement

Coinbase Tightens the Bounty Rules

Coinbase moved fast on this. On July 29, the exchange narrowed its Web2 bug bounty program to focus only on high, critical, and extreme vulnerabilities. Lower-severity stuff is basically out now. The top reward stays at $1 million for anyone who finds an extreme vulnerability — that figure hasn’t changed. And Coinbase runs a separate program called Cantina specifically for blockchain and smart-contract issues, so the Web2 tightening doesn’t touch that side of things.

The restructuring of the bounty criteria is a direct response to the AI submission flood. When your review queue is dominated by low-quality automated reports, the fix isn’t to hire more reviewers — it’s to raise the bar for what gets reviewed at all. Whether that works long-term is unclear, but it’s the move Coinbase made.

Real Vulnerabilities Found Amid the Noise

Not everything coming in is garbage, though. External researchers Joe Almeida and Anh Nguyen found a real one. They identified a vulnerability in Coinbase’s Stellar withdrawal reconciliation process. Because of how Stellar’s fee-bump mechanism works, a specific set of conditions could cause Coinbase to count a single transaction twice internally. That’s a double-counting problem — not trivial. Coinbase paused the affected process, pushed a fix, and confirmed the correction before resuming normal operations. Customer funds were never at risk, and there’s no evidence anyone exploited it beyond internal testing.

Separately, an AI-assisted audit of Bitcoin security flagged 4,962 potential issues across 390 repositories in under 28 hours. That’s a wild number. But only one-fifth of those were independently verified. The rest still need human validation to confirm whether they’re actual vulnerabilities or more noise. So even when AI finds something, humans still have to clean up behind it.

AI as Both Tool and Threat

The irony here is that AI is creating the problem and also being used to hunt for solutions. On the threat side, the FBI has warned that generative AI lets criminals produce convincing phishing messages faster and automate malicious activity at scale. That’s not theoretical anymore. Investigators found that North Korea-linked group Kimsuky has been using AI platforms to generate phishing materials aimed at virtual assets, financial investments, and software development targets. The sophistication of those campaigns is growing.

And the broader numbers are bad. A comprehensive onchain security assessment found 212 exploits in the first half of 2026, with losses hitting $1.1 billion across the digital asset sector. That’s the environment Coinbase is operating in — one where the financial stakes for missing a real bug are enormous, and the cost of reviewing fake ones is eating up serious resources.

Coinbase’s approach tries to thread that needle. AI tools scan for potential issues at scale. Specialist researchers handle the deeper work — protocol rules, internal accounting, the stuff that requires actual judgment. It’s not a perfect system, but it’s probably the only one that makes sense right now.

The exchange is also cutting about 700 jobs as part of a broader restructuring aimed at improving efficiency, partly by leaning harder into AI-driven productivity. So Coinbase is simultaneously fighting AI-generated junk submissions and betting on AI to make its own operations leaner.

The 4% valid rate in the first half of 2026 is the number that sticks.

Frequently Asked Questions

What percentage of Coinbase bug bounty reports were valid in the first half of 2026?

Only 4% of HackerOne submissions to Coinbase were considered valid and paid out during the first half of 2026, down from 14% in 2024.

Who found the Stellar withdrawal vulnerability at Coinbase?

External researchers Joe Almeida and Anh Nguyen identified the vulnerability involving Coinbase’s Stellar withdrawal reconciliation process; Coinbase paused the process, fixed it, and confirmed customer funds were unaffected.

Community Trust IndexHigh Confidence
85%
Real
Real85%15%Fake
26 community signals

Jean-Luc Maracon

Jean-Luc Maracon is a French-Swiss expert in decentralized finance, known for his sharp analysis of Bitcoin, European Web3 projects, and crypto regulatory challenges. Splitting his time between Geneva and Paris, he brings a unique perspective blending traditional finance with blockchain innovation. He regularly collaborates with crypto platforms across Europe to help make digital investing more accessible. Specialties: Bitcoin, staking, European regulation, crypto security, Web3.

Advertisement

Related Stories