Only 4% of Coinbase Security Reports Earned Rewards as AI-Driven Submissions Reshaped Bug Bounty Program
Coinbase changed its bug bounty program after seeing a sharp rise in low-quality security reports. The crypto exchange said artificial intelligence has made it easier to send duplicate and less useful reports. The new rules came into effect on July 29 and apply only to its Web2 program on HackerOne.
The company has stopped paying rewards for low and medium severity bugs. It also reduced rewards for more serious findings. High severity payouts dropped from $15,000 to $6,000, while critical bug rewards fell from $50,000 to $15,000. Coinbase said its own security systems can already find many smaller issues, allowing outside researchers to focus on more difficult security problems.
Coinbase Cuts Bug Bounty Rewards
Coinbase shared numbers to explain the decision. During the first six months of 2026, 44% of closed reports were duplicates, 37% included issues that could not be exploited, and 15% were invalid. Only 4% of all reports qualified for rewards. The company said AI has increased the number of reports, although most of them do not help improve security.
The exchange also said skilled security researchers remain important. Human experts can still find complex bugs that automated tools often fail to detect. Coinbase wants its bug bounty program to reward those advanced findings instead of common issues.
Web3 Security Program Stays Unchanged
These changes affect only the HackerOne Web2 program. The company’s Web3 security program on Cantina will continue without any changes. Coinbase said smart contract reviews still require experienced researchers with deep technical knowledge.
Coinbase is not alone in making this move. GitHub recently changed its GitHub bug bounty program after facing a similar increase in AI-generated reports. The platform reduced public rewards and created a separate private program for trusted researchers.
AI Reshapes Bug Bounty Programs
The latest changes show how AI cybersecurity is changing bug bounty programs. Companies now want fewer reports with better quality, while experienced researchers continue to play a key role in finding serious security risks.
Disclaimer : Crypto News India does not recommend that any cryptocurrency should be bought, sold, or held by you. Do conduct your own due diligence and consult your financial advisor before making any investment decisions.
