Coinbase has launched a $5 million bug bounty program hosted on Cantina aimed at strengthening the security of its on-chain products and Base Layer 2 network.
The program, that was announced on July 8 is one of the largest of its kind in web3 and aims to identify and fix critical vulnerabilities in Coinbase’s smart contracts. Security researchers are encouraged to submit their findings through Cantina’s platform, which enables repeatable and structured assessments.
Each submission is reviewed by experienced triagers and rewards are based on how significant and serious each finding is. Coinbase has emphasized the importance of clear, actionable submissions that can lead to quick resolutions.
A landmark moment in onchain security.@Coinbase has launched a $5M bug bounty on Cantina, a new program focusing exclusively on all its onchain products and @base’s smart contracts. It sets a new standard for securing Web3 organizations at scale. Details below. pic.twitter.com/otO5QVTtH4
— Cantina 🪐 (@cantinasecurity) July 8, 2025
This program builds on Coinbase’s previous collaboration with Cantina, which included audits of key components such as WebAuthn modules, Verified Pools, and Nitro Validators. These earlier reviews formed the basis for a larger, open-access program that now includes Base’s smart contracts and other on-chain systems.
The launch also comes at a time when security remains a top priority for Coinbase. In May, the company suffered a high-profile data breach involving bribed support staff. Instead of paying the attackers’ ransom, Coinbase created a $20 million reward fund for information that could help identify and prosecute those responsible.
The company has since taken several steps to improve internal controls and increase overall safety standards. In addition to its work with Coinbase, Cantina has become a major force in Web3 security.
The platform streamlines review workflows and reduces low-value submissions by combining AI-powered tools with expert-led triage. Cantina has also hosted major programs such as Uniswap’s (UNI) $15.5 million bounty for version 4 of the protocol.
The new bug bounty reflects Coinbase’s continued shift toward open collaboration with the security research community. It also extends protection for Base, the company’s Ethereum (ETH) layer 2 network, and complements similar efforts by Optimism (OP) to secure the OP Stack.