Latest news about Bitcoin and all cryptocurrencies. Your daily crypto news habit.
Coinbase, one of the worldâs largest cryptocurrency exchanges, announced it will actively participate in Hackeroneâs âHack the Worldâ project, offering 50,000 USD for a first-place remote code execution. Itâs the companyâs effort to extend its bug bounty program in hopes of remaining âtop-of-[the]-marketâ with regard to security.
Also read:Â Coinbase Plans to Call the Fork With the Most Accumulated Difficulty âBitcoinâ
âCoinbase Loves Bug Bountiesâ
Bug bounties are an increasingly used initiative by businesses to find code issues and security problems through incentivized hacking. Bounty payouts reward hackers to expose companies to problems before potential bad-actors might.
Head of Security for Coinbase, Philip Martin, blogged, âWeâre thankful to all the security researchers who have worked hard to find and report vulnerabilities.â
Instead of researchers âfacing a choice between using a vulnerability themselves,â he urged, âselling a vulnerability to 3rd parties or giving a vulnerability away for free, bounties present a good, legal, risk-adjusted return for the time invested by a researcher.â
To date, Coinbase has disclosed 73 discovered vulnerabilities.
Mr. Martin emphasized bounties âde-criminalize the actions of good-faith security researchers, while still forbidding malicious hacking.â
Though most proposals are not relevant, Coinbase finds value in bug bounties.
Over five years, the exchange has âpaid out $176,031 in bounties to 223 researchers across 346 valid reports out of a total of 3101 reports submitted,â Mr. Martin noted.
This year, Coinbase joins a competition hosted by Hackerone, Hack the World. An unsigned blog post stated the ventureâs goals as âto help build stronger relationships between our hackers and our customers, reward high signal and high impact reports, and to have some fun along the way by giving out some awesome prizes to our top hackers.â
Sponsors range from Uber, Github, and Airbnb, to Mapbox and Dropbox.
Coinbase is offering âthe top 3 most impactful bugs submitted, as part of Hack The World, an additional $10,000, $7,500 and $5,000,â he explained. ââMost Impactfulâ will be judged by the Coinbase security team on a combination of bug severity, system criticality and report quality.â
The companyâs Hack the World payouts are ranked as âRemote Code Execution: $50,000; Significant manipulation of account balance: $10,000; XSS/CSRF/Clickjacking affecting sensitive actions: $7,500; Theft of privileged information: $5,000; Partial authentication bypass: $3,000â respectively, among other lesser tasks.
Bitcoin, Safe and Easy
This does not mean storing bitcoin on the exchange is safe. In fact, âthere have been months when Coinbase users have been robbed as often as 30 timesâa rate of one robbery every single day,â according to Fortune.
CEO Brian Armstrong tells Fortune, âWe need to be held to a higher standard because digital currency is so new and interesting and powerful that it is attractive to a lot of people out there to try to steal it.â The exchange holds usersâ keys, allowing them ease of access to trading through mere passwords.
Thefts are generally on the customer side, exploiting weaknesses at mobile phone carrier companies such as Sprint and Verizon.
Hack The World competition formally ends on November 18.
What do you think about hacking bounties? Tell us in the comments below!
Images courtesy of Creative Commons, Pixabay, and Coinbase.Â
At Bitcoin.com thereâs a bunch of free helpful services. For instance, check out our Tools page!
The post Coinbase Offers $50,000 Hack the World Bug Bounty appeared first on Bitcoin News.
Disclaimer
The views and opinions expressed in this article are solely those of the authors and do not reflect the views of Bitcoin Insider. Every investment and trading move involves risk - this is especially true for cryptocurrencies given their volatility. We strongly advise our readers to conduct their own research when making a decision.