The report
Coinbase says autonomous adversarial testing has moved from occasional research into continuous production-scale security operations. Its Continuous Adversarial Testing platform includes source-code review, prompt-injection testing, agent-skill trust checks, MCP registry scanning, DAST and Web2-to-smart-contract boundary testing.
The SHADE component assigns repositories to dedicated agents that hunt for exploitable vulnerabilities. Coinbase reports more than 150,000 scans since mid-2026, including over 128,000 pull-request reviews.
The control design is as important as the scan count: Rules of Engagement are enforced server-side and again at tool execution, and production state changes are blocked unless a target is explicitly scoped as non-production.