Bitcoin News: Coinbase Says AI Noise Could Triple Bug Reports

Coinbase is seeing a sharp rise in bug bounty submissions, with volume on pace to triple this year as AI-generated reports swell its review queue. Despite the surge, only 4% of reports submitted via HackerOne in the first half of the year were validated and paid, highlighting a growing triage burden for the exchange’s security team.

AI-Driven Surge, Low Validation Rate

The influx of AI-generated or AI-assisted submissions is contributing to a larger share of low-value or non-actionable reports. While overall activity is rising, the validation rate remains low, underscoring the challenge of filtering credible vulnerabilities from noise before fixes and rewards can be issued.

Key data points

  • Bug bounty submissions are on track to triple year over year.
  • Only 4% of reports filed through HackerOne in the first half were accepted as valid, paid bugs.

Why It Matters

For a leading cryptocurrency exchange, rapid and accurate triage of vulnerability disclosures is critical to safeguarding platform integrity and customer funds. A higher volume of low-quality reports can slow validation and remediation workflows, increasing the need for experienced reviewers and improved filtering to prioritize high-impact findings.

Human Review Remains Central

Despite broader adoption of tooling to streamline intake, final assessments of severity and exploitability continue to rely on human analysts. Coinbase’s security reviewers are tasked with separating credible threats from false positives and informational submissions before issuing rewards through its bug bounty program on HackerOne, a platform that connects ethical hackers with organizations seeking responsible vulnerability disclosure.

×