Coinbase: AI bug reports could triple, valid bugs fall to 4%
Coinbase warned AI-generated vulnerability submissions may triple HackerOne volume and reported only 4% of first-half 2026 reports were valid paid bugs.
Coinbase reported in an Aug. 11 security disclosure that the volume of vulnerability submissions is on track to reach three times last year’s total after doubling the previous year. The company linked the surge to inexpensive AI tools that let researchers scan software and generate reports quickly, but it did not provide a precise share of submissions produced by automated tools.
The share of reports that qualified as valid, paid bugs fell from 14% in 2024 to 4% in the first half of 2026 for issues submitted through HackerOne, a third-party platform where independent researchers disclose software vulnerabilities for possible rewards.
Among HackerOne reports closed in the first half, 44% were duplicates, 37% contained information without an exploitable flaw, and 15% were invalid. On July 29 Coinbase narrowed its public Web2 bounty program to accept only high, critical and extreme severity vulnerabilities. A separate Cantina program continues to handle blockchain and smart-contract issues. Extreme vulnerabilities remain eligible for rewards up to $1 million. Web3 rewards were left unchanged.
External researchers Joe Almeida and Anh Nguyen reported a reconciliation flaw tied to Stellar withdrawals. Stellar’s fee-bump mechanism allows a third party to wrap a transaction and pay a higher network fee without new signatures. Under some conditions Coinbase’s system could mark the original transaction as failed even after the transfer succeeded onchain, creating a risk that internal accounting could count spending twice. Coinbase paused the affected process, applied a correction and restored normal operations. The company reported customer funds were not affected and found no evidence of exploitation beyond the researchers’ proof of concept and internal testing. AI separately flagged a related, less severe deposit-side defect.
An AI-assisted Bitcoin audit flagged 4,962 potential findings across 390 repositories during a 27.5-hour review. About one-fifth of those alerts had been independently reproduced at the time of publication; the remainder required human confirmation before they could be treated as established vulnerabilities.
Law enforcement and security analysts have warned that attackers are using generative AI to scale phishing, impersonation and credential-theft campaigns. The FBI cautioned that AI can make malicious messages more convincing and automate operations. Investigations have linked AI-generated materials to campaigns tied to North Korea-linked actors and to services that intercept two-factor authentication tokens. A coordinated disruption removed 330 domains tied to a 2FA-phishing service known as Tycoon.
For consumers the direct effects are limited. Faster, AI-driven attacks can make phishing more convincing, while the increase in low-value bug reports mainly raises the workload for company security teams. Coinbase reported it is expanding automated screening while keeping specialist researchers for complex protocol and accounting issues.
Industry data for the first half of 2026 recorded 212 exploits and roughly $1.1 billion in onchain losses. Standard precautions for users of cryptocurrency services remain secure wallet backups, strong passwords and two-factor authentication.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








