Robinhood

Robinhood

@robinhood
Live
Cantina-Triaged

Maximum reward

$1,000,000

Severity

Max. Reward

Critical

$1,000,000

High

$100,000

Medium

$25,000

Low

$5,000

Deposit required

$30

Findings submitted

5

Start date

8 Sep 2026

KYC

Required to join

Please sign in as a researcher to join the bounty.

Log in

Robinhood Markets has launched its onchain footprint with Robinhood Chain, an AI-native and purpose-built for real-world assets environment for builders to innovate seamlessly. This bug bounty program covers the smart contracts that power tokenization on Robinhood Chain, the just-in-time spending for Robinhood's crypto wallet, the public web interfaces and documentation portals, and the testnet faucet and explorer.

Severity Definitions

Web3 (Smart Contracts + Onchain Configuration)

  • Critical - Direct theft of tokenized assets or user balances, unauthorized mint/burn of Robinhood-issued tokenized assets, permanent freezing of funds, complete compromise of privileged roles or of Robinhood's upgrade/configuration authority over the onchain contracts, arbitrary code execution on live contracts.
  • High - Temporary freezing of funds >24h, theft of unclaimed yield or pending JIT spending balances, manipulation of Robinhood's onchain price inputs (multiplier/pause) affecting tokenization mint/redeem, access control bypass on an in-scope Robinhood contract under specific state conditions.
  • Medium - Temporary freezing <24h, griefing without direct profit, DoS on specific tokenization or JIT contracts, token-standard compliance failures, replay across testnet/mainnet or multi-chain contexts.
  • Low - Input sanitization issues without security impact.

Web2 (Web Interfaces, Docs, Explorer, and Faucet)

  • Critical - RCE on a Robinhood-operated in-scope backend (e.g., the faucet), or SQLi or SSRF on a Robinhood-operated backend leading to data exfiltration.
  • High - Stored or reflected XSS on an in-scope Robinhood web surface (the /chain landing page, docs, or the Robinhood explorer instance), SSRF from an in-scope Robinhood backend reaching internal services, subdomain takeover on *.chain.robinhood.com, insufficient access controls on the faucet admin interface or the Robinhood-managed explorer configuration.
  • Medium - CSRF on state-changing actions, DoS via resource exhaustion on non-critical endpoints, session fixation, open redirect.
  • Low - Reverse tabnabbing, clickjacking of a state-changing action, or a verbose error / stack trace that leaks exploitable internal detail.

In addition to the above definitions, we will also use the Cantina Bug Bounty Severity Classification Framework to determine severity.

Prohibited Actions

  • No Unauthorized Testing on Production Environments: Do not test vulnerabilities on mainnet or public testnet deployments without prior authorization. Use local test environments or private test setups. The testnet faucet and explorer are available for safe testing - use those rather than mainnet probes.
  • No Public Disclosure Without Consent: Do not publicly disclose details of any vulnerability before it has been addressed and you have received written permission from Robinhood to disclose.
  • No Exploitation or Data Exfiltration: Do not exploit the vulnerability beyond the minimum steps necessary to demonstrate the issue. Do not access private data, engage in social engineering, or disrupt service.
  • No Conflict of Interest: Individuals currently or formerly employed by Robinhood Markets, Inc. or its affiliates, or external vendors who have tested or contributed to the development of the affected service, product, code, or contract in the past 6 months, are ineligible to participate.

Eligibility

To be eligible for a reward, you must:

  • Be the first to report a previously unknown, non-public vulnerability within scope.
  • Provide sufficient information to reproduce and fix the issue.
  • Not have exploited the vulnerability in a malicious manner.
  • Not have disclosed the vulnerability to third parties prior to receiving permission from Robinhood.
  • Comply with all program rules and applicable laws.

No reward will be paid for vulnerabilities already identified, under active remediation, or resolved by Robinhood prior to receipt of the report. You must also be of legal age in your jurisdiction and not reside in a country under OFAC sanctions or other applicable restrictions.

Other Terms

By submitting a report, you grant Robinhood Markets, Inc. the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of Robinhood Markets, Inc. The terms, conditions, and scope of this program may be revised at any time. Participants are responsible for reviewing the latest version before submitting a report.

Reports should be made through the Cantina Platform as soon as possible - ideally within 24 hours of discovery. Include a clear description of the vulnerability, steps to reproduce (proof of concept preferred), conditions under which the issue occurs, and potential implications if exploited.