A research index for disclosed web3 bugs

Coin Buggie ingests already-public, closed bug bounty disclosures and post-mortems from Immunefi, Code4rena, Sherlock, Cantina and HATs Finance, then normalizes each platform's own format into a single report schema: protocol, chain or VM, vulnerability category, severity tier, payout, disclosure date, audit firm, TVL at time of report, and the full technical write-up.

Disclosure hygiene

Only reports that are already public and closed are surfaced. Active, embargoed or unpatched vulnerability data is never ingested, stored or published — the review queue in the admin console exists to enforce that before anything reaches the public index.

Vulnerability taxonomy

Start searching reports →