THE APEX TIMES
Coinbase cuts bug bounty payouts for lower-severity security issues, citing AI-driven focus
The exchange adjusted its HackerOne bug bounty program on July 29, removing rewards for low- and medium-severity vulnerabilities and reducing payouts for high-severity findings, according to reporting.
Coinbase has changed the rewards structure for its external security bug bounty program, dropping payments for lower-severity vulnerabilities and reducing rewards for its highest-severity category, effective immediately, according to a July 29 report.
The update was made to Coinbase’s publicly listed HackerOne program, a platform that coordinates vulnerability disclosures and pays bounties to researchers who report security weaknesses responsibly. Bug bounty programs are often used by large online platforms to supplement internal security testing, with the expectation that paying for timely reports can reduce the time attackers have to exploit known issues.
Under the revised structure described in the report, rewards for low- and medium-severity vulnerabilities were removed. At the same time, the reported top-tier payout was reduced, with high-severity rewards falling from $15,000 to $6,000. The reporting also said Coinbase attributed the change to “AI,” though it did not provide further operational detail on how AI affected the company’s risk model or reward economics.
The timing matters, because the program adjustments were described as taking effect immediately on July 29. That means researchers who submit vulnerability reports after the change would be subject to the updated reward schedule, rather than the prior payouts.
Coinbase has not disclosed in the reported account the precise criteria it uses to classify severity levels, nor did it describe any new testing thresholds or internal process changes tied to AI. Companies sometimes adjust bug bounty policies when they believe the likelihood of certain classes of vulnerabilities is declining, or when automation is improving detection and triage. In this case, however, the report does not specify which of those explanations is driving the decision beyond citing AI.
For the broader industry, the move indicates that bug bounty programs are not static. As vendors change their security posture, move to new technology stacks, or refine how they prioritize vulnerabilities, the reward schedule can shift. For researchers, those changes can affect the economics of disclosure work, especially if they reduce the chance of a paid outcome for some categories of findings.
Still, key details remain unclear from the public reporting. The report does not specify whether Coinbase changed the scope of what is eligible for testing, whether there are exceptions for certain high-impact classes of issues, or whether the company’s internal severity rubric changed alongside the payout changes. It also does not explain whether the AI reference relates to how Coinbase triages reports, how it detects vulnerabilities, or how it forecasts attacker behavior.
What to watch next is whether Coinbase publishes an expanded explanation or updated terms on its HackerOne program page, including how severity is defined after the change and whether the company will adjust payouts again in response to researcher feedback. Researchers may also look for any guidance on which vulnerability types Coinbase now deems most urgent enough to qualify for rewards under the new structure.
Why It Matters
- Adjusting bug bounty payouts can change researcher incentives, especially for vulnerability reports that would previously qualify as low or medium severity.
- Lower payouts for high-severity findings could reduce the number of high-announcement reports if researchers reassess the return on effort.
- The AI explanation suggests Coinbase may be altering how it prioritizes security risks, but the lack of specifics leaves uncertainty about how severity and scope decisions are made.
- For security ecosystems, the move underscores that bounty programs can be re-priced quickly, which may influence disclosure timing and strategy.
Key Facts
- Coinbase changed its HackerOne bug bounty program on July 29, with changes described as taking effect immediately.
- The update removed rewards for low- and medium-severity vulnerabilities.
- High-severity rewards were reduced from $15,000 to $6,000, according to the report.
- The report said Coinbase attributed the changes to AI, without additional detail.
Finance Related
Berkshire Hathaway CEO Greg Abel to Appear on TV in Rare Interview, With Focus Likely on Insurance and BNSF
In a Wednesday interview, Berkshire Hathaway’s chief executive Greg Abel is expected to address developments across the conglomerate’s major operating units, including insurance and its BNSF railroad business.
Coinbase expands Webull crypto trading footprint into Canada
The Coinbase platform is powering an expansion of Webull’s crypto trading in Canada, extending the exchange’s role as a provider of core digital-asset market infrastructure as demand grows.
Morgan Stanley’s 2026 Stock Rally Faces a Familiar Test: Interest-Rate Volatility and the $250 Question
Shares of Morgan Stanley have climbed close to a breakout level in 2026, but a recent rate-driven selloff has underscored how quickly sentiment can shift for big Wall Street lenders. The next hurdle for bulls remains whether the stock can decisively clear the $250 mark.
Morgan Stanley flags concerns about U.S. debt as investors may be focusing on the wrong risk, Yahoo Finance reports
A Morgan Stanley view highlighted in a Yahoo Finance report suggests bond investors could be over-weighting U.S. debt worries while missing other forces that may matter more for markets.
Bank of America points to “hidden value” in fintech Affirm, arguing the stock’s outlook is being understated
In a fresh investor note highlighted by Yahoo Finance, Bank of America said Affirm’s own growth indicators are not getting full credit from the market, and urged investors to look beyond the most obvious valuation outlines.
E*TRADE from Morgan Stanley publishes monthly sector rotation dashboard showing client net buying and selling
The broker’s monthly study tracks whether clients were net buyers or net sellers across 11 core stock market sectors, providing a high-level read on investor positioning shifts.
JPMorgan gains momentum as the 10-year Treasury yield pushes toward 4.8%
In market trading on Sept. 1, JPMorgan Chase shares moved higher as bond yields rose, a backdrop that can lift bank earnings via higher interest income. The shift followed reporting that the bank’s net interest income climbed 10% to $25.6 billion.
Jim Cramer delivers blunt take on Coinbase’s August momentum
In a late-August market discussion, Jim Cramer challenged the enthusiasm around Coinbase’s stock after a run that he previously flagged as among Wall Street’s standouts.
Bank of America downgrades PG&E to Neutral, citing California wildfire reforms that do not fully de-risk liabilities
Bank of America said California’s latest wildfire legislation did not deliver the durable liability and financing framework it wants to see, cutting PG&E Corp. from Buy to Neutral.
BlackRock (BLK) slips more than the market as shares close down 2.38%
BlackRock shares fell in the latest session, closing at $1, a drop that outpaced the broader market move reported alongside the company’s stock update.