Coinbase Prime has launched an internal security platform called CAT (Continuous Adversarial Testing) that uses autonomous AI agents to identify vulnerabilities across its infrastructure, applications, and smart-contract integrations on an ongoing basis. The platform represents a shift away from traditional point-in-time security assessments, enabling the cryptocurrency exchange to match the cadence and scale of modern threat actors who operate continuously and leverage AI tools themselves.

  • Coverage Areas: Web and mobile applications, backend services, infrastructure, Web2-to-smart-contract integrations, and internal AI tooling
  • Testing Capabilities: New code scanning, existing code analysis, dynamic testing, mobile assessment (OWASP Top 10 and MASVS), and infrastructure enumeration
  • Key Features: Automated PR security review at commit and merge stages, attack-surface monitoring with auto-discovery, Web3 boundary testing, prompt injection detection, and interactive pentesting with engineer collaboration
  • Safeguards: Server-side Rules of Engagement enforced at two independent layers, deny-list overrides, and bounded test windows to prevent unauthorized scope expansion

CAT integrates across Coinbase‘s development lifecycle, automatically scanning every code commit and product launch without requiring manual requests. The platform monitors newly discovered services and endpoints in real time, immediately queuing them for testing upon detection. Specialized components handle mobile applications through comprehensive OWASP assessments, Web3 connections through boundary testing between backend code and smart contracts, and infrastructure through non-destructive continuous scanning mapped to recognized security methodologies including NIST SP 800-115 and MITRE ATT&CK frameworks.

The platform includes an interactive pentesting feature called Live Operative, which pairs engineers with AI agents to conduct threat-modeling-focused security assessments. Rather than repeating automated findings, the system proposes adversarial scenarios for human approval and escalates decisions requiring human judgment, such as authentication workflows.

Security controls prevent autonomous agents from exceeding authorized scope. CAT’s Rules of Engagement are versioned, server-side policies applied at two independent enforcement layers: once when work is queued and again structurally in the scanner before any network traffic is generated. Deny lists override all scope parameters, and test windows restrict when assessments can execute.

By Gavriel Gavrielides

Gavriel Gavrielides is the Founder and Chief Editor of fintech-intelligence. An ACA-qualified finance executive, he previously served as Group CFO and Global Head of Accounting & Finance for a major international Forex broker with over 800 employees, following a foundational career as an auditor at a Big Four firm. Having spent over 15 years navigating complex international regulatory frameworks, scaling financial infrastructure, and managing global corporate strategies, Gavriel launched fintech-intelligence because he recognized that the traditional boundaries between finance and technology have completely dissolved. He saw a critical need for an industry publication driven by actual operational expertise rather than outside commentary. Today, Gavriel leverages his deep institutional background to cut through the market noise, delivering high-signal, deeply analytical insights into the technologies, regulations, and innovations reshaping the future of money. Connect with Gavriel on https://www.linkedin.com/in/gavriel-gavrielides-103734124/