Coinbase reduced its HackerOne bug bounty rewards and removed payouts for low- and medium-severity vulnerabilities 🛡️

High-severity rewards fell by 60%, while critical payouts were reduced by 70% 📉

The company said AI has increased the number of duplicate and low-value vulnerability reports.

Coinbase now wants researchers to focus on complex, high-impact security issues 🔍

The changes apply only to Coinbase's Web2 program, while its Web3 bug bounty remains unchanged.

GitHub also lowered public bug bounty rewards and introduced an invitation-only program for trusted researchers 💻

Both companies are adapting their security programs as AI reshapes vulnerability research.

Today's Pill - as AI automates basic security testing, companies are placing greater value on human expertise for finding critical vulnerabilities 🔄
1