BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Coinbase changes security rewards, blames AI

Coinbase changed its public HackerOne bug bounty program on July 29, removing rewards for low- and medium-severity vulnerabilities with immediate effect. High-severity rewards fell from $15,0

AnonymousCryptoCompass newsroom
July 29, 2026
3 min read
NEWS
Coinbase changes security rewards, blames AI
CryptoCompass editorial visual for altcoins coverage.

Coinbase changed its public HackerOne bug bounty program on July 29, removing rewards for low- and medium-severity vulnerabilities with immediate effect. 

High-severity rewards fell from $15,000 to $6,000, a reduction of $9,000, or 60%. Critical payouts dropped from $50,000 to $15,000, a cut of $35,000, or 70%. 

HackerOne is a bug bounty platform where companies pay independent security researchers to identify and responsibly disclose software vulnerabilities.

The crypto exchange blamed the changes on a surge in low-value reports accelerated by artificial intelligence. 

Related: Cathie Wood predicts more shutdowns and bankruptcies

During the first half of 2026, 44% of closed reports were duplicates, 37% were informative but not exploitable and 15% were invalid. Just 4% led to payouts.

Source: Coinbase

“AI has changed who — or what — finds a ‘commodity’ vulnerability, and it has changed how fast and how cheaply that can happen,” Coinbase said.

The company said its internal tools can now continuously detect many lower-severity issues. It wants external researchers to focus on difficult vulnerabilities that require domain expertise and creativity.

The changes apply only to Coinbase’s Web2 program on HackerOne. Its Cantina program for Web3 and smart contract vulnerabilities remains unchanged.

GitHub also cuts public bug bounty payouts

Coinbase is not the only technology company changing how it rewards security researchers.

GitHub introduced a two-tier bug bounty system for reports submitted from July 27. It divided the program into a lower-paying public tier and an invitation-only tier for trusted researchers.

The Microsoft-owned platform cited a growing backlog of low-effort, low-quality and AI-generated reports.

Public rewards fell to fixed payments of $250 for low-severity bugs, $2,000 for medium findings, $5,000 for high-severity flaws and $10,000 for critical vulnerabilities.

GitHub previously offered ranges of $500 to $1,000 for low-severity reports and as much as $30,000 for critical findings.

Researchers invited to its private program can earn about three to four times the public rates. GitHub is also introducing a HackerOne signal requirement, giving new researchers limited opportunities to establish a reliable record.

Bug bounties became a major security business

Bug bounty programs have developed into a major cybersecurity incentive system.

HackerOne’s 2023 report found that 80% of surveyed ethical hackers participated to earn money, while nearly one-quarter hacked full time. Many others also held jobs in cybersecurity.

Financial services and internet services were among the most attractive targets, drawing interest from 53% and 58% of hackers, respectively.

Three years later, automated submissions are affecting program economics. HackerOne’s 2025 report said 67% of surveyed researchers used AI or automation in their workflows, while valid AI-related vulnerability reports rose 210% year over year.

The report also found that hackbots were strongest at identifying surface-level flaws. Human reasoning, however, remains essential for business logic and system-level vulnerabilities.

Coinbase and GitHub are now adjusting rewards around that divide. Their programs increasingly favor creativity, difficult vulnerabilities and critical exploits over report volume.

Related: Americans who lost money in a crypto bankruptcy get a second chance