Coinbase rewards researcher $250,000 for discovering "market-nuking" bug


Those are two words that can capture a trader's attention in crypto. And when an anonymous account Tree of Alpha used those words to describe a possible exploit on Coinbase, it sent crypto Twitter into a tizzy about the extent to which Coinbase could be exploited.

Ultimately, those words were accurate to describe what could have happened if Coinbase’s leadership did not identify and fix what Tree of Alpha found.

In a blog post, Coinbase said that the problem was a bug in the new trading feature in limited beta availability. An exploiter, using two accounts, could manually modify their APIs connected to the exchange to sell a certain amount in one asset if they had the same amount in the other account with the same amount of another crypto.


Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

“The user submits a market order to the BTC-USD order book to sell 100 BTC, but manually edits their API request to specify their SHIB account as the source of funds,” Coinbase explained. “As a result, a market order to sell 100 BTC on the BTC-USD order book would be entered on the Coinbase Exchange,” the firm added.

Coinbase said it would pay Tree of Alpha $250,000 as a bounty — a figure that’s dwarfed by the bounties paid by DeFi protocols. Wormhole offered to pay out $10 million after its eye-popping hack earlier this month.

As for Coinbase’s bug, Tree of Alpha said that he discovered it whilst poking around Coinbase’s new advanced trading platform. “I just used 0.0243 ETH to sell 0.0243 BTC on the BTC-USD pair, a pair I do not have access to, without holding any BTC,” he explained. “Hoping this is a UI bug, I check the fills on the order, and they match the API: those trades really happened, on the live order book.”

In other words, Tree of Alpha was able to sell ~$1,000 worth of bitcoin with only ~$70 worth of ether in his account (rough maths based on February 11 pricing).

About Author

Frank Chaparro is the Editor At Large at The Block. Chaparro started his career at Business Insider, where he specialized in the intersection of digital assets and Wall Street, market structure, and financial technology. Soon after joining Business Insider out of Fordham University, Chaparro was interviewing top finance and tech executives, including billionaire Mark Cuban, “Flash Boys” star Brad Katsuyama, Cboe Global Markets CEO Ed Tilly, and New York Stock Exchange President Tom Farley. In 2018, he become a sought after reporter in the crypto world, interviewing luminaries such as Tyler Winklevoss, the cofounder of Gemini, Jeremy Allaire, the CEO of Circle, and Fundstrat head Tom Lee. He runs his own podcast The Scoop and writes a biweekly eponymous newsletter. He leads special projects, including The Block's flagship podcast, The Scoop. Prior to The Block, he held roles at Business Insider, NPR, and Nasdaq. For inquiries or tips, email [email protected].