Blockchain
Coinbase clarifies bug bounty policy in response to Uber extortion verdict – Crypto News
In a blog post on November 30, Coinbase sought to clarify its bug bounty program policies in response to the recent Uber data breach verdict.
The company stated that it still welcomes “responsible” disclosure of security issues, but users who abuse this process will not be awarded bug bounties:
“The key word in all of this is ‘responsible’. In the wake of the recent Uber verdict, there is a lot of concern in the industry about bug bounty submissions becoming extortion attempts. At Coinbase, […] we’ve put a lot of thought into how we operate our bug bounty program to stay on the right side of the law.”
The verdict Coinbase was referring to was issued on October 5. Joe Sullivan, former Uber security chief, was found guilty of colluding with attackers to cover up evidence of a data breach, according to a report by the Washington Post. Sullivan had originally claimed that the attackers had submitted the breach as a bug bounty and that the company had paid them as a bug bounty reward.
Tech companies often use bug bounties to encourage white hat hackers to find security vulnerabilities and report them. But the Sullivan verdict has raised the question of how far a bug bounty program can go in awarding prizes to hackers without running afoul of the law itself.
In its post, Coinbase stated that it has encountered some bug bounty participants who claim to have committed criminal actions that would prevent the company from being able to legally make a payout.
For example, a participant submitted multiple emails to the team saying that they had “306 million users’ data fully dehashed” and a “bypass” to skip the 48 hour waiting period on new devices. According to Coinbase, if this person had such information, it would mean that they accessed customer data beyond what could be considered “good faith” or “accidental.” In such a case, Coinbase would not be able to pay the bounty.
In this particular case, Coinbase said they believed that the participant was making a false claim. The participant did not provide any information that would allow the claim to be verified, so the team ignored the request for a bounty. But even if the person making the claim had been telling the truth, it would have been illegal to pay out the reward to them.
Coinbase also emphasized that threats or other extortion attempts will not result in a bug bounty payout:
“Most important of all — a bug bounty submission can never contain threats or any attempts at extortion. We are always open to paying bounties for legitimate findings. Ransom demands are an entirely different matter.”
The practice of paying bug bounties is sometimes controversial. Critics say it can encourage malicious behavior, while supporters say it often allows vulnerabilities to be discovered safely. On Oct. 19, an attacker drained the Moola Market DeFi app of $9 million worth of cryptocurrency. But when the developer offered to let the attacker keep $500K as a bug bounty, the attacker returned the other $8.5 million.
A similar attack occurred on the decentralized exchange, KyberSwap, in September. In this case, the attackers stole $265K, and the developers offered to let them keep 15% of the funds if they would return the rest. Suspects in the case were later identifiedbut the funds have not been returned, and the hackers appear to still be at large.
-
Blockchain1 week agoXRP Price Gains Traction — Buyers Pile In Ahead Of Key Technical Breakout – Crypto News
-
Technology1 week agoSam Altman says OpenAI is developing a ‘legitimate AI researcher’ by 2028 that can discover new science on its own – Crypto News
-
De-fi7 days agoBittensor Rallies Ahead of First TAO Halving – Crypto News
-
De-fi1 week agoNearly Half of US Retail Crypto Holders Haven’t Earned Yield: MoreMarkets – Crypto News
-
Technology1 week agoMicrosoft ‘tricked users into pricier AI-linked 365 plans,’ says Australian watchdog; files lawsuit – Crypto News
-
De-fi1 week agoAI Sector Rebounds as Agent Payment Systems Gain Traction – Crypto News
-
Blockchain1 week agoBig Iran Bank Goes Bankrupt, Affecting 42 Million Customers – Crypto News
-
Business1 week ago
Crypto Market Rally: BTC, ETH, SOL, DOGE Jump 3-7% as US China Trade Talks Progress – Crypto News
-
Blockchain1 week agoIBM Set to Launch Platform for Managing Digital Assets – Crypto News
-
Technology1 week ago
Ethereum Supercycle Strengthens as SharpLink Gaming Withdraws $78.3M in ETH – Crypto News
-
others1 week agoGBP/USD floats around 1.3320 as softer US CPI reinforces Fed cut bets – Crypto News
-
De-fi1 week agoNearly Half of US Retail Crypto Holders Haven’t Earned Yield: MoreMarkets – Crypto News
-
Cryptocurrency1 week agoWestern Union eyes stablecoin rails in pursuit of a ‘super app’ vision – Crypto News
-
others1 week ago
Indian Court Declares XRP as Property in WazirX Hack Case – Crypto News
-
Blockchain1 week agoSolana Eyes $210 Before Its Next Major Move—Uptrend Or Fakeout Ahead? – Crypto News
-
De-fi1 week agoREP Jumps 50% in a Week as Dev Gets Community Support for Augur Fork – Crypto News
-
De-fi7 days agoBitcoin Dips Under $110,000 After Fed Cuts Rates – Crypto News
-
De-fi1 week agoNearly Half of US Retail Crypto Holders Haven’t Earned Yield: MoreMarkets – Crypto News
-
Blockchain1 week agoXRP/BTC Retests 6-Year Breakout Trendline, Analyst Calls For Decoupling – Crypto News
-
Cryptocurrency1 week agoUSDJPY Forecast: The Dollar’s Winning Streak Why New Highs Could Be At Hand – Crypto News
-
De-fi1 week agoMetaMask Fuels Airdrop Buzz With Token Claim Domain Registration – Crypto News
-
De-fi1 week agoTokenized Nasdaq Futures Enter Top 10 by Volume on Hyperliquid – Crypto News
-
Technology1 week agoBenQ MA270U review: A 4K monitor that actually gets MacBook users right – Crypto News
-
others1 week ago
Is Changpeng “CZ” Zhao Returning To Binance? Probably Not – Crypto News
-
Business1 week ago
Crypto ETFs Attract $1B in Fresh Capital Ahead of Expected Fed Rate Cut This Week – Crypto News
-
Cryptocurrency1 week agoInside Bitwise’s milestone solana ETF launch – Crypto News
-
Business7 days agoStarbucks Says Turnaround Strategy Drives Growth in Global Sales – Crypto News
-
Technology1 week agoSurvival instinct? New study says some leading AI models won’t let themselves be shut down – Crypto News
-
others1 week agoGold weakens as US-China trade optimism lifts risk sentiment, focus turns to Fed – Crypto News
-
Cryptocurrency1 week agoGold Price Forecast 2025, 2030, 2040 & Investment Outlook – Crypto News
-
Metaverse1 week agoIt isn‘t just AI. Earnings and the economy show the rally has legs. – Crypto News
-
Cryptocurrency1 week agoKERNEL price goes vertical on Upbit listing, hits $0.23 – Crypto News
-
Cryptocurrency1 week agoCitigroup and Coinbase partner to expand digital-asset payment capabilities – Crypto News
-
Cryptocurrency1 week agoWhy Is Pi Network’s (PI) Price Up by Double Digits Today? – Crypto News
-
De-fi1 week agoCrypto Market Edges Lower While US Stocks Hit New Highs – Crypto News
-
others1 week ago
Can ASTER Price Rebound 50% as Whale Activity and Bullish Pattern Align? – Crypto News
-
Technology7 days agoGiving Nvidias Blackwell chip to China would slash USs AI advantage, experts say – Crypto News
-
others5 days agoMETA stock has lower gaps to fill – Crypto News
-
Blockchain1 week agoThe Bitcoin Stock-To-Flow ModelIsn’t the Best BTC Forecast Model: Analyst – Crypto News
-
Metaverse1 week agoIt isn‘t just AI. Earnings and the economy show the rally has legs. – Crypto News
-
Cryptocurrency1 week ago
Is Stock Tokenization Really Exploding? Not Even 0.01% – Crypto News
-
De-fi1 week agoCRO Jumps After Trump’s Truth Social Announces Prediction Market Partnership with Crypto.Com – Crypto News
-
Technology1 week ago
Breaking: $2.6B Western Union Announces Plans for Solana-Powered Stablecoin by 2026 – Crypto News
-
Blockchain1 week agoVisa To Support Four Stablecoins on Four Blockchains – Crypto News
-
others1 week ago
Pi Coin Gains Another 15% As Pi Network Joins ISO 20022 For Seamless Banking Integration – Crypto News
-
others1 week agoBank of Canada set to cut interest rate for second consecutive meeting – Crypto News
-
Cryptocurrency1 week ago‘Moments of the Unknown’: Justin Aversano Shares Globetrotting Love Letter to Humanity – Crypto News
-
others1 week ago
GBP flat vs. USD with notably muted reaction to retail sales & PMI data – Scotiabank – Crypto News
-
Cryptocurrency1 week agoUSDJPY Forecast: The Dollar’s Winning Streak Why New Highs Could Be At Hand – Crypto News
-
Cryptocurrency1 week agoXRP Reversal Sends Price Towards $1, DOGE Treasury to Go Public, Bitcoin Beats Gold, Binance’s CZ Pardoned — Top Weekly Crypto News – Crypto News
