CoinMate.io Program Statistics


View program

2 total issues disclosed

$0 total paid publicly

Most disclosed (1 disclosures) — Improper Authentication - Generic



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
POST /api/bitcoinWithdrawalFees returns financial data without authentication despite being documented as a USER OPERATION (private endpoint) Improper Authentication - Generic glferreira-devsecops Medium 2026-05-20
HMAC signature verification omits endpoint and payload allowing request forgery on CoinMate API Missing Required Cryptographic Step glferreira-devsecops Low 2026-05-20