Coinbase reduced its HackerOne bug bounty rewards and removed payouts for low- and medium-severity vulnerabilities ๐Ÿ›ก๏ธ

High-severity rewards fell by 60%, while critical payouts were reduced by 70% ๐Ÿ“‰

The company said AI has increased the number of duplicate and low-value vulnerability reports.

Coinbase now wants researchers to focus on complex, high-impact security issues ๐Ÿ”

The changes apply only to Coinbase's Web2 program, while its Web3 bug bounty remains unchanged.

GitHub also lowered public bug bounty rewards and introduced an invitation-only program for trusted researchers ๐Ÿ’ป

Both companies are adapting their security programs as AI reshapes vulnerability research.

Today's Pill - as AI automates basic security testing, companies are placing greater value on human expertise for finding critical vulnerabilities ๐Ÿ”„
2