Coinbase Pays Bug Bounty For Trading Interface Flaw

Share post:

Coinbase has rewarded a researcher with $250,000 for uncovering a flaw in the platform’s trading interface.

The bounty, the company’s highest payment, was paid to a researcher named “Tree _ of _ Alpha.”

The researcher warned Coinbase via Twitter of a “potentially marketing-nuking” bug that requires an urgent patch.

Immediately, Coinbase received a report about HackerOne from the researcher and the company got to work.

“The underlying cause of the bug was a missing logic validation check in a Retail Brokerage API endpoint, which allowed a user to submit trades to a specific order book using a mismatched source account. This API is only utilized by our Retail Advanced Trading platform, which is currently in limited beta release,” Coinbase said.

Coinbase explained that even if exploited, the vulnerability cannot be exploited for large-scale attacks because “Coinbase Exchange has automatic price protection circuit breakers.” In addition, its trade surveillance team monitors markets for anomalous trading activity.

For more information, read the original story in ZDNet.

SUBSCRIBE NOW

Related articles

Ransomware Surge Targets U.S. Energy and Utilities Sector Amid Legacy System Challenges: Report

A recent Trustwave SpiderLabs report underscores the growing cybersecurity challenges in the U.S. energy and utilities sector, driven...

FortiGate Configuration Leak Exposes Thousands of Organizations

A recent security incident has resulted in the exposure of nearly 5,000 organizations' email addresses and IP information...

Credentials from Top Cybersecurity Vendors Found on Dark Web For $10 Each

A report by security researchers at Cyble has uncovered a troubling discovery: thousands of account credentials from several...

Hamilton Estimates $52 Million to Rebuild IT Systems After Ransomware Attack

The city of Hamilton plans to spend $52 million over the next three years to rebuild and secure...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways