Coinbase’s bug bounty volume is on track to triple as AI-generated submissions flood its review queue, yet only 4% of first-half HackerOne reports were valid paid bugs. Human reviewers must separate credible threats from a growing wave of low-value reports.
Key Takeaways
Report volume remains on pace to triple from last year.Only 4% of first-half reports submitted through Hackerone were valid paid bugs.Human researchers uncovered a Stellar flaw that AI missed.The rising volume coincided with a smaller share of credible discoveries. Coinbase indicated that the valid-report share fell from 14% in 2024 to 4% during the first half of 2026. The company associated researchers’ growing AI use with a sharp increase in AI-generated reports but did not specify what percentage of total submissions involved automated tools.
What Did Human Researchers Find?Coinbase’s system could treat the original transaction as failed under certain conditions even after the intended transfer succeeded onchain. That discrepancy created the potential for spending to be counted twice internally. Coinbase paused the affected process, confirmed a correction, and restored normal processing.
Customer funds remained unaffected, and Coinbase found no evidence of exploitation beyond the researchers’ proof of concept and internal testing. AI separately flagged a related, less severe deposit-side defect. The findings illustrate Coinbase’s intended division between automated screening and specialist investigations involving protocol rules and internal accounting.
How Are Criminals Applying AI? What Does the AI Security Shift Mean for Consumers?


















