Coinbase

Coinbase

@coinbase
Live

Maximum reward

$5,000,000

Severity

Max. Reward

Critical

$5,000,000

High

$500,000

Medium

$50,000

Low

$5,000

Findings submitted

78

Start date

8 Jul 2025

KYC

Required to join

Please sign in as a researcher to join the bounty.

Log in

In scope

Severity

Min and Max Reward

Critical

Up to $5,000,000


High

Up to $500,000


Medium

Up to $50,000


Low

Up to $5,000


Informational

Up to $0

We have three products in Tier 0: Base, cbBTC, and cbETH.

AssetDescriptionScope
BaseAn L2 that rolls up to Ethereum (L1). L2 & L1 mainnet addresses as specified here
cbBTCWrapped BTC, backed 1:1 by Coinbase. Contracts on Base, Ethereum, Solana, and Arbitrum — and any other networks we may add in the future — as specified here
cbETHWrapped staked ETH that represents ETH staked through Coinbase. Contracts on Ethereum as specified here

Out of scope

Out of scope targets

The following types of contracts will not be in scope:

  • Contracts deployed on testnets and devnets
  • Contracts deployed on mainnet for testing purposes
  • Contracts deployed on mainnet for internal use
  • Third-party dependencies of any of our contracts
  • Third-party contracts that may be used by Coinbase to provide certain services

Default out of scope

  • Issues found in previous security reviews
  • Third-party contracts not under direct project control
  • Issues with non-standard ERC20 tokens (unless explicitly supported by the project)
  • Rounding errors with no significant impact
  • User errors requiring obviously incorrect parameter inputs
  • Vulnerabilities that only manifest during extreme market conditions
  • Incorrect data from third-party oracles
    • Note: Oracle manipulation and flash loan attacks are still in scope
  • Theoretical exploits without practical proof-of-concept
  • Issues requiring access to leaked keys or credentials
  • Issues arising from Sybil attacks
  • Centralization risks
  • Basic economic and governance attacks (such as 51% attacks)
  • Protocol design choices
  • Gas optimization issues and high gas costs
  • Best practice suggestions
  • Submissions generated using ChatGPT or other LLM tools