Published Invest3 min read
Coinbase Stops Paying for Small Bugs Because AI Made Small Bugs Free to Find
Submissions are projected to triple after doubling, while the share that earns a bounty fell from 14 percent to 4 percent. The response is a narrower reward surface, not a bigger triage team.
Context for builders, not their beat.See today for builders

What happened
- Coinbase says the volume of bug reports submitted through its programs is projected to reach three times the previous year's total, following a doubling the year before.
- The surge in submissions is linked to growing use of AI by external researchers, which has made it far easier and cheaper to scan codebases and generate submissions at scale.
- Valid reports that result in paid bounties dropped from 14 percent in 2024 to 4 percent in the first half of 2026.
- A large portion of closed reports consisted of duplicates, non-exploitable informational findings, or invalid claims.
- Coinbase adjusted its public Web2 bug bounty program on HackerOne so that low- and medium-severity issues are no longer eligible for rewards, narrowing the focus to high, critical, and extreme vulnerabilities.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Coinbase has removed low- and medium-severity findings from the reward scope of its public Web2 bug bounty program on HackerOne, leaving payouts only for high, critical, and extreme issues [5]. The reason is arithmetic: the company says submission volume is on track to reach three times the previous year's total after doubling the year before [1], while the proportion of reports that end in a paid bounty has fallen from 14 percent in 2024 to 4 percent in the first half of 2026 [3].
Stack those two figures and the triage problem gets concrete. Two years of a doubling followed by a tripling implies roughly six times the 2024 report volume [12]. Meanwhile the paid-valid rate has dropped by about 10 percentage points, a relative decline of roughly 71 percent [13]. Six times the reports at four-fourteenths of the hit rate works out to something like 1.7 times as many genuinely payable findings [14] - more real bugs, bought with far more screening labour. Coinbase attributes the volume to external researchers using AI, which has made scanning codebases and generating submissions cheap at scale [2], and describes much of the closed pipeline as duplicates, non-exploitable informational findings, or invalid claims [4].
The rest of the recalibration is modest. Reward amounts for high and critical findings were adjusted to market conditions, and the maximum payout for extreme-severity issues stays at one million dollars [6]. The separate program covering crypto and smart contract vulnerabilities was left untouched [7]. Coinbase's stated aim is to cut the screening burden on internal reviewers and push researcher effort toward problems current AI tools do not find reliably [8]. Worth noting the mechanism here: removing a reward removes the incentive to submit, but it does not remove the ability to submit. Whether the low-value flow actually thins out is the test of this policy, not the policy itself.
Coinbase's argument for where humans still earn their keep rests on one example it disclosed. External researchers found a reconciliation problem involving Stellar withdrawals and the protocol's fee-bump feature, where under specific conditions a completed on-chain transfer could be recorded internally as failed, creating double-counting risk [9]. According to Coinbase, spotting it required understanding both the blockchain protocol and the company's internal accounting logic, and AI did not surface it, though AI did flag a related and less severe issue on the deposit side [10]. No customer funds were affected and the issue was remediated [11]. That is a clean illustration of the split the company is betting on: automated tooling, which Coinbase says has matured enough to catch many common issues at scale [15], handles volume, and humans handle the flaws that need context.
What to watch: whether the 4 percent paid rate stabilises or keeps sliding once low and medium findings carry no reward, since a falling rate on rising volume is the signal that scope narrowing did not work. Watch also whether the crypto and smart contract program stays exempt as AI submissions spread - Coinbase notes similar increases in AI-assisted reports across crypto and open-source projects [16] - and whether large programs elsewhere follow by pricing out the bottom two severity tiers rather than paying triage staff to read them.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Coinbase says the volume of bug reports submitted through its programs is projected to reach three times the previous year's total, following a doubling the year before.
- [2]
The surge in submissions is linked to growing use of AI by external researchers, which has made it far easier and cheaper to scan codebases and generate submissions at scale.
- [3]
Valid reports that result in paid bounties dropped from 14 percent in 2024 to 4 percent in the first half of 2026.
ReportedView cited source - [4]
A large portion of closed reports consisted of duplicates, non-exploitable informational findings, or invalid claims.
ReportedView cited source - [5]
Coinbase adjusted its public Web2 bug bounty program on HackerOne so that low- and medium-severity issues are no longer eligible for rewards, narrowing the focus to high, critical, and extreme vulnerabilities.
ReportedView cited source - [6]
Reward amounts for high and critical findings were recalibrated to align with market conditions, while the maximum payout for extreme-severity issues remains at one million dollars.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- crowdfundinsider.comOmar FaridiAug 13Coinbase Anticipates AI Influx of Bug Reports to Increase Significantly, Adding to Digital Security Noise
Additional citations
- Coinbase, via Crowdfund Insider
- Coinbase


