Loading market data...

Coinbase Bug Bounty Flooded by AI-Generated Reports, Only 4% Valid

Coinbase Bug Bounty Flooded by AI-Generated Reports, Only 4% Valid
tag. We'll have

And

inside. We'll also need meta description 150-160 chars, keywords, focusKeyword. Let's craft. Title: "Coinbase Bug Bounty Volume Triples as AI Submissions Overwhelm Reviewers" Slug: "coinbase-bug-bounty-ai-submissions-triple" Content:

Coinbase's bug bounty program is on track to triple its submission volume this year, driven largely by AI-generated reports. But the surge comes with a catch: only 4% of the reports filed in the first half of the year through HackerOne were valid, paid bugs. That leaves human reviewers with a growing pile of low-value submissions to sift through.

The AI Flood

The volume of reports hitting Coinbase's bug bounty queue is growing at a pace that's hard to ignore. According to the company's own data, submissions are on track to triple compared to the previous year. The culprit? A wave of AI-generated reports that are flooding the system.

These aren't the kind of carefully crafted vulnerability disclosures that security teams dream about. Many are automated, repetitive, and often miss the mark entirely. The result is a review queue that's swelling with noise, making it harder for the real issues to get the attention they deserve.

The 4% Reality

Here's the stark number: only 4% of the reports submitted through HackerOne in the first half of the year turned out to be valid, paid bugs. That means 96% of the submissions were either duplicates, false positives, or simply not security issues at all.

For the human reviewers tasked with triaging these reports, that's a lot of wasted effort. Every low-value submission takes time to evaluate, and with the volume tripling, that time adds up quickly. The screening burden is real, and it's only getting heavier.

Human Reviewers in the Middle

The challenge isn't just about volume. It's about separating credible threats from a growing wave of low-value reports. Human reviewers have to look at each submission, assess its validity, and decide whether it's worth escalating. With AI-generated reports flooding in, that job becomes a game of whack-a-mole.

It's a problem that's not unique to Coinbase, but the company is feeling it acutely. The bug bounty program is a critical part of its security strategy, and if the noise drowns out the signal, real vulnerabilities could slip through the cracks.

For now, the burden falls on the reviewers. They're the ones who have to wade through the AI-generated chaff to find the few genuine bugs that deserve a payout. It's a tedious, time-consuming process, and it's only going to get more challenging as the volume continues to climb.

What remains unclear is how Coinbase will adapt its review process to keep pace with the surge. The company hasn't said whether it plans to invest in automated triage tools or change its reward structure to discourage low-quality submissions. For now, the human reviewers are on the front lines, and the flood shows no signs of receding.