{"id":76738,"date":"2026-08-13T05:20:32","date_gmt":"2026-08-13T05:20:32","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/coinbase-says-bug-reports-could-triple-as-ai-adds-security-noise\/"},"modified":"2026-08-13T05:20:32","modified_gmt":"2026-08-13T05:20:32","slug":"coinbase-says-bug-reports-could-triple-as-ai-adds-security-noise","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/coinbase-says-bug-reports-could-triple-as-ai-adds-security-noise\/","title":{"rendered":"Coinbase Says Bug Reports Could Triple as AI Adds Security Noise"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Report volume remains on pace to triple from last year.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Only 4% of first-half reports submitted through Hackerone were valid paid bugs.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Human researchers uncovered a Stellar flaw that AI missed.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>Why Are Coinbase\u2019s Bug Reports Surging?<\/h2>\n<p>Human reviewers face a growing screening burden as inexpensive AI tools allow security researchers to scan software and produce vulnerability reports rapidly. Crypto exchange Coinbase (Nasdaq: COIN) outlined the trend Aug. 11 in its security disclosure, reporting that <a href=\"https:\/\/www.coinbase.com\/blog\/consumer-protection-tuesday-ai-and-human-expertise\" target=\"_blank\" rel=\"noopener noreferrer\">submissions are on track to reach three times last year\u2019s volume<\/a> after doubling the year before.<\/p>\n<p>The rising volume coincided with a smaller share of credible discoveries. Coinbase indicated that the valid-report share fell from 14% in 2024 to 4% during the first half of 2026. The company associated researchers\u2019 growing AI use with a sharp increase in AI-generated reports but did not specify what percentage of total submissions involved automated tools.<\/p>\n<p>Coinbase <a href=\"https:\/\/www.coinbase.com\/blog\/focusing-our-bug-bounty-program-on-what-matters-most-in-the-age-of-ai\" target=\"_blank\" rel=\"noopener noreferrer\">narrowed its Web2 bug bounty program<\/a> on July 29 to high, critical, and extreme vulnerabilities. Among Hackerone reports closed during the first half, 44% were duplicates, 37% contained information without an exploitable flaw, and 15% were invalid. Extreme vulnerabilities remain eligible for rewards of up to $1 million. Hackerone is an external platform where independent researchers submit software vulnerabilities to companies for review and possible rewards. Coinbase uses the Web2 label for conventional websites, applications, and supporting services. Its separate Cantina program covers blockchain and smart-contract vulnerabilities.<\/p>\n<h2>What Did Human Researchers Find?<\/h2>\n<p>External researchers Joe Almeida and Anh Nguyen discovered a subtle weakness involving Coinbase\u2019s reconciliation of Stellar withdrawals. <a href=\"https:\/\/developers.stellar.org\/docs\/build\/guides\/transactions\/fee-bump-transactions\" target=\"_blank\" rel=\"noopener noreferrer\">Stellar\u2019s fee-bump mechanism<\/a> allows a third party to wrap an existing transaction and pay a higher network fee without requiring new signatures or sequence-number management.<\/p>\n<p>Coinbase\u2019s system could treat the original transaction as failed under certain conditions even after the intended transfer succeeded onchain. That discrepancy created the potential for spending to be counted twice internally. Coinbase paused the affected process, confirmed a correction, and restored normal processing.<\/p>\n<p>Customer funds remained unaffected, and Coinbase found no evidence of exploitation beyond the researchers\u2019 proof of concept and internal testing. AI separately flagged a related, less severe deposit-side defect. The findings illustrate Coinbase\u2019s intended division between automated screening and specialist investigations involving protocol rules and internal accounting.<\/p>\n<p>A separate AI-assisted Bitcoin security audit <a href=\"https:\/\/news.bitcoin.com\/security\/bitcoin-red-team-audit-coldcard-vulnerabilities\/\">produced 4,962 potential findings across 390 repositories<\/a> during a 27.5-hour review. About one-fifth had been independently reproduced at publication, leaving human confirmation necessary before the remaining alerts could be treated as established vulnerabilities.<\/p>\n<h2>How Are Criminals Applying AI?<\/h2>\n<p>Attackers can deploy the same technology to accelerate phishing, impersonation, and credential theft. The Federal Bureau of Investigation warned that <a href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\/sanfrancisco\/news\/fbi-warns-of-increasing-threat-of-cyber-criminals-utilizing-artificial-intelligence\" target=\"_blank\" rel=\"noopener noreferrer\">generative AI helps criminals produce convincing messages faster<\/a>, automate operations, and expand their pool of potential targets.<\/p>\n<p>An Aug. 10 analysis of North Korea-linked Kimsuky activity <a href=\"https:\/\/news.bitcoin.com\/security\/report-north-koreas-kimsuky-turns-ai-into-a-crypto-hacking-weapon\/\">identified AI platforms and generated documents across associated infrastructure<\/a>. Investigators observed phishing material aimed at virtual assets, financial investment, and software development targets.<\/p>\n<p>A March 6 report on the Tycoon 2FA phishing service described technology that <a href=\"https:\/\/news.bitcoin.com\/coinbase-microsoft-europol-disrupt-major-phishing-platform-330-domains-taken-down\/\">intercepted active sessions and captured tokens used to bypass multifactor authentication<\/a>. A coordinated disruption removed 330 domains tied to the operation.<\/p>\n<h2>What Does the AI Security Shift Mean for Consumers?<\/h2>\n<p>For consumers, AI can increase attack speed and make phishing messages more convincing, while bug bounty volume primarily affects company review teams. A July 30 onchain security assessment <a href=\"https:\/\/news.bitcoin.com\/security\/security-firm-blockaid-says-212-onchain-exploits-stole-1-1b-as-ai-and-wallet-attacks-accelerate\/\">counted 212 exploits and $1.1 billion in losses<\/a> during the first half of 2026.<\/p>\n<p>Individual precautions remain relevant while exchanges expand automated reviews and retain specialized researchers. <a href=\"https:\/\/www.bitcoin.com\/get-started\/wallet-security\/privacy-protection\/digital-asset-security\/\" target=\"_blank\" rel=\"noopener noreferrer\">Standard digital asset security practices<\/a> include secure wallet backups, strong password management, and two-factor authentication. Coinbase\u2019s revised program leaves Web3 rewards unchanged while concentrating its public Web2 bounty payments on high-impact flaws.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/coinbase-says-bug-reports-could-triple-as-ai-adds-security-noise\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Report volume remains on pace to triple from last year. Only 4% of first-half reports submitted through Hackerone were valid paid bugs. Human researchers uncovered a Stellar flaw that AI missed. Why Are Coinbase\u2019s Bug Reports Surging? Human reviewers face a growing screening burden as inexpensive [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":76739,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76738"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=76738"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76738\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/76739"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=76738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=76738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=76738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}