Key Takeaways
- Report volume remains on pace to triple from last year.
- Only 4% of first-half reports submitted through Hackerone were valid paid bugs.
- Human researchers uncovered a Stellar flaw that AI missed.
Human reviewers face a growing screening burden as inexpensive AI tools allow security researchers to scan software and produce vulnerability reports rapidly. Crypto exchange Coinbase (Nasdaq: COIN) outlined the trend Aug. 11 in its security disclosure, reporting that submissions are on track to reach three times last year’s volume after doubling the year before.
The rising volume coincided with a smaller share of credible discoveries. Coinbase indicated that the valid-report share fell from 14% in 2024 to 4% during the first half of 2026. The company associated researchers’ growing AI use with a sharp increase in AI-generated reports but did not specify what percentage of total submissions involved automated tools.
Coinbase narrowed its Web2 bug bounty program on July 29 to high, critical, and extreme vulnerabilities. Among Hackerone reports closed during the first half, 44% were duplicates, 37% contained information without an exploitable flaw, and 15% were invalid. Extreme vulnerabilities remain eligible for rewards of up to $1 million. Hackerone is an external platform where independent researchers submit software vulnerabilities to companies for review and possible rewards. Coinbase uses the Web2 label for conventional websites, applications, and supporting services. Its separate Cantina program covers blockchain and smart-contract vulnerabilities.
External researchers Joe Almeida and Anh Nguyen discovered a subtle weakness involving Coinbase’s reconciliation of Stellar withdrawals. Stellar’s fee-bump mechanism allows a third party to wrap an existing transaction and pay a higher network fee without requiring new signatures or sequence-number management.
Coinbase’s system could treat the original transaction as failed under certain conditions even after the intended transfer succeeded onchain. That discrepancy created the potential for spending to be counted twice internally. Coinbase paused the affected process, confirmed a correction, and restored normal processing.
Customer funds remained unaffected, and Coinbase found no evidence of exploitation beyond the researchers’ proof of concept and internal testing. AI separately flagged a related, less severe deposit-side defect. The findings illustrate Coinbase’s intended division between automated screening and specialist investigations involving protocol rules and internal accounting.
A separate AI-assisted Bitcoin security audit produced 4,962 potential findings across 390 repositories during a 27.5-hour review. About one-fifth had been independently reproduced at publication, leaving human confirmation necessary before the remaining alerts could be treated as established vulnerabilities.
Attackers can deploy the same technology to accelerate phishing, impersonation, and credential theft. The Federal Bureau of Investigation warned that generative AI helps criminals produce convincing messages faster, automate operations, and expand their pool of potential targets.
An Aug. 10 analysis of North Korea-linked Kimsuky activity identified AI platforms and generated documents across associated infrastructure. Investigators observed phishing material aimed at virtual assets, financial investment, and software development targets.
A March 6 report on the Tycoon 2FA phishing service described technology that intercepted active sessions and captured tokens used to bypass multifactor authentication. A coordinated disruption removed 330 domains tied to the operation.
For consumers, AI can increase attack speed and make phishing messages more convincing, while bug bounty volume primarily affects company review teams. A July 30 onchain security assessment counted 212 exploits and $1.1 billion in losses during the first half of 2026.
Individual precautions remain relevant while exchanges expand automated reviews and retain specialized researchers. Standard digital asset security practices include secure wallet backups, strong password management, and two-factor authentication. Coinbase’s revised program leaves Web3 rewards unchanged while concentrating its public Web2 bounty payments on high-impact flaws.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。