A research index for disclosed web3 bugs
Coin Buggie ingests already-public, closed bug bounty disclosures and post-mortems from Immunefi, Code4rena, Sherlock, Cantina and HATs Finance, then normalizes each platform's own format into a single report schema: protocol, chain or VM, vulnerability category, severity tier, payout, disclosure date, audit firm, TVL at time of report, and the full technical write-up.
Disclosure hygiene
Only reports that are already public and closed are surfaced. Active, embargoed or unpatched vulnerability data is never ingested, stored or published — the review queue in the admin console exists to enforce that before anything reaches the public index.
Vulnerability taxonomy
- Reentrancy
- Oracle manipulation
- Flash loan attack
- Access control
- Integer overflow/underflow
- Signature replay
- Front-running / MEV
- Bridge exploit
- Price manipulation
- Logic error
- Governance attack