# Robinhood Chain launches a bug bounty on Cantina > Robinhood Chain's public bug bounty is live on Cantina, with rewards up to $1,000,000 for eligible findings across smart contracts and public applications. Author: Cantina Published: September 28, 2026 Topics: Robinhood Chain, Bug Bounty, Smart Contract Security, Web3 Canonical URL: https://www.cantina.security/blog/robinhood-chain-bug-bounty Robinhood Chain has launched a public bug bounty on Cantina, with rewards up to **$1,000,000 for eligible findings**. The program covers the contracts behind Stock Tokens and Just-In-Time Funding, critical network configuration, and public services, including its documentation, faucet, and block explorers. [Robinhood Chain](https://docs.robinhood.com/chain/) supports Stock Tokens and other tokenized real-world assets. The new bounty gives security researchers a clear way to test the systems that move value, control access, update prices, and connect public applications. ## What's in scope? The highest-priority areas include: - Contracts that create and manage Stock Tokens - Access controls, pause controls, and upgrade safety - Just-In-Time Funding and signature-authorized withdrawals - Pricing and corporate-action controls - Robinhood-managed bridge and network settings - Public documentation, faucets, explorers, and web interfaces ## What should researchers look for? Relevant findings include unauthorized transfers, creation or destruction of tokens, frozen funds, signature or replay flaws, broken access controls, unsafe upgrades, and configuration errors. The public application scope also includes server-side code execution, request forgery, SQL injection, cross-site scripting, subdomain takeover, and access-control failures. ## Check the scope before testing The program covers Robinhood-operated systems and Robinhood-specific configuration. Vulnerabilities in third-party infrastructure should be reported to the respective provider unless Robinhood's implementation or configuration caused the issue. Testnet findings can receive full severity when the same issue can be demonstrated on mainnet. Researchers should show the mainnet path without exploiting production. Follow the program's testing rules and use local or private test environments where required. Read the full scope and join the Robinhood Chain bug bounty.