Skip to content

Commit e7fde11

Browse files
Add SECURITY.md (#167)
1 parent 503363d commit e7fde11

1 file changed

Lines changed: 22 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# Security
2+
3+
## Bug bounty program
4+
5+
In line with our strategy of being the safest way for users to access crypto:
6+
7+
+ Coinbase extended our [best-in-industry](https://www.coinbase.com/blog/celebrating-10-years-of-our-bug-bounty-program) million-dollar [HackerOne bug bounty program](https://hackerone.com/coinbase?type=team) to cover the Base network and Base infrastructure.
8+
9+
+ Coinbase has launched a 5 million-dollar [Cantina bug bounty program](https://cantina.xyz/code/55316f42-3c5e-4746-9bd0-0f18dcbc344b) to cover all deployed smart contracts for Base, and those used as part of Coinbase products and services.
10+
11+
## Reporting vulnerabilities
12+
13+
All potential vulnerability reports can be submitted via the following platforms:
14+
15+
1. [**HackerOne**](https://hackerone.com/coinbase): For offchain components and services.
16+
For more information on reporting vulnerabilities and our HackerOne bug bounty program, view our [security program policies](https://hackerone.com/coinbase?view_policy=true).
17+
18+
2. [**Cantina**](https://cantina.xyz/bounties/55316f42-3c5e-4746-9bd0-0f18dcbc344b): For deployed smart contracts.
19+
For more information on what smart contracts are considered within the scope of the Cantina bug bounty program, view our [Tier 0](https://cantina.xyz/code/55316f42-3c5e-4746-9bd0-0f18dcbc344b/overview?overviewTab=1&assetGroup=0) and [Tier 1](https://cantina.xyz/code/55316f42-3c5e-4746-9bd0-0f18dcbc344b/overview?overviewTab=1&assetGroup=1) scope guides.
20+
21+
22+
For all other security related inquiries, please reach out to [security@coinbase.com](mailto:security@coinbase.com).

0 commit comments

Comments
 (0)