Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All articles

Company News

Robinhood Chain launches a bug bounty on Cantina

Robinhood Chain's public bug bounty is live on Cantina, with rewards up to $1,000,000 for eligible findings across smart contracts and public applications.

Cantina 2 min read
Robinhood Chain Bug Bounty Smart Contract Security Web3
On this page

Robinhood Chain has launched a public bug bounty on Cantina, with rewards up to $1,000,000 for eligible findings. The program covers the contracts behind Stock Tokens and Just-In-Time Funding, critical network configuration, and public services, including its documentation, faucet, and block explorers.

Robinhood Chain supports Stock Tokens and other tokenized real-world assets. The new bounty gives security researchers a clear way to test the systems that move value, control access, update prices, and connect public applications.

Robinhood and Cantina bug bounty program, with rewards up to $1,000,000.

What’s in scope?

The highest-priority areas include:

  • Contracts that create and manage Stock Tokens
  • Access controls, pause controls, and upgrade safety
  • Just-In-Time Funding and signature-authorized withdrawals
  • Pricing and corporate-action controls
  • Robinhood-managed bridge and network settings
  • Public documentation, faucets, explorers, and web interfaces

What should researchers look for?

Relevant findings include unauthorized transfers, creation or destruction of tokens, frozen funds, signature or replay flaws, broken access controls, unsafe upgrades, and configuration errors.

The public application scope also includes server-side code execution, request forgery, SQL injection, cross-site scripting, subdomain takeover, and access-control failures.

Check the scope before testing

The program covers Robinhood-operated systems and Robinhood-specific configuration. Vulnerabilities in third-party infrastructure should be reported to the respective provider unless Robinhood’s implementation or configuration caused the issue.

Testnet findings can receive full severity when the same issue can be demonstrated on mainnet. Researchers should show the mainnet path without exploiting production. Follow the program’s testing rules and use local or private test environments where required.

Read the full scope and join the Robinhood Chain bug bounty.