> ## Documentation Index
> Fetch the complete documentation index at: https://base-a060aa97-fix-review-b20-doc.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Reporting Vulnerabilities

> The Base procedures for reporting vulnerabilities.

## Bug bounty program

In line with our strategy of being the safest way for users to access crypto:

* Coinbase extended our [best-in-industry](https://www.coinbase.com/blog/celebrating-10-years-of-our-bug-bounty-program) million-dollar [HackerOne bug bounty program](https://hackerone.com/coinbase?type=team) to cover the Base network and Base infrastructure.
* Coinbase has launched a 5 million-dollar [Cantina bug bounty program](https://cantina.xyz/code/55316f42-3c5e-4746-9bd0-0f18dcbc344b) to cover all deployed smart contracts for Base, and those used as part of Coinbase products and services.

## Reporting vulnerabilities

Submit potential vulnerability reports via the appropriate platform below:

1. [**HackerOne**](https://hackerone.com/coinbase) — For offchain components and services. All reports are triaged around the clock by Coinbase engineers with domain knowledge. For more information, view our [security program policies](https://hackerone.com/coinbase?view_policy=true).

2. [**Cantina**](https://cantina.xyz/bounties/55316f42-3c5e-4746-9bd0-0f18dcbc344b) — For deployed smart contracts. For more information on what smart contracts are within scope, view the [Tier 0](https://cantina.xyz/code/55316f42-3c5e-4746-9bd0-0f18dcbc344b/overview?overviewTab=1\&assetGroup=0) and [Tier 1](https://cantina.xyz/code/55316f42-3c5e-4746-9bd0-0f18dcbc344b/overview?overviewTab=1\&assetGroup=1) scope guides.

For all other security-related inquiries, contact [security@coinbase.com](mailto:security@coinbase.com).
