Robinhood

Robinhood

@robinhood
Live
Cantina-Triaged

Maximum reward

$1,000,000

Severity

Max. Reward

Critical

$1,000,000

High

$100,000

Medium

$25,000

Low

$5,000

Deposit required

$30

Findings submitted

5

Start date

8 Sep 2026

KYC

Required to join

Please sign in as a researcher to join the bounty.

Log in

In scope

Severity

Min and Max Reward

Critical

Up to $1,000,000


High

Up to $100,000


Medium

Up to $25,000


Low

Up to $5,000

In Scope

  • Tokenized stock contracts: the stock token, its factory, the access-control registry, the scaled-balance / multiplier logic, and the oracle-pause module. Includes unauthorized mint or burn, access-control flaws, blocklist or pause bypass, seizure (admin-burn and re-mint) abuse, and storage-layout / upgrade-safety bugs.
  • Just-In-Time Funding contract: Robinhood's signature-authorized withdrawal contract for ETH and ERC-20. Includes signature-verification and authorization flaws, replay (nonce) and expiry bypass, access-control flaws across its admin, authorizer, withdrawer, and pauser roles, and abuse of the emergency-withdraw or pause logic.
  • Canonical bridge and rollup configuration: the canonical Arbitrum contracts used by Robinhood Chain (rollup, delayed inbox, bridge, outbox, and CoreProxyAdmin) have public addresses on docs.robinhood.com/chain/protocol-contracts; bridging is documented at docs.robinhood.com/chain/bridging. The contract code is Arbitrum-authored and out of scope (Arbitrum's program). In scope: misconfiguration of the parameters and access controls Robinhood sets for these contracts, which are readable onchain from the public addresses.

Access-control flaws that let an unauthorized caller write the oracle multiplier or pause state are Tier 1 findings (see Tier 2 for the pricing logic itself).

Rewards are proposed maximums pending final Robinhood sign-off. Actual payouts are at Robinhood's discretion based on report quality, completeness, and exploitability.

Name
Description
Asset
StockFactory

stock token factory

AccessControlsRegistry

access-control registry

Stock Tokens & Tokenized ETFs

stock tokens, scaled-balance / multiplier logic, oracle-pause module

Just-In-Time Funding

Signature-authorized withdrawal contract for ETH and ERC-20

Canonical Bridge & Rollup Configuration

Arbitrum rollup, delayed inbox, bridge, outbox, and CoreProxyAdmin - Robinhood-set parameters and access controls only (contract code is Arbitrum-authored and out of scope)

Out of scope

The following issues are out of scope and not eligible for rewards.

For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.

L2 / Chain-Specific

  • The Arbitrum node software (Nitro and ArbOS) and the sequencer, public RPC, and feed endpoints that run it. Robinhood Chain is an Arbitrum chain; protocol-level bugs in this software are covered by Arbitrum's bug bounty program.
  • Validator software and operations (operated by Offchain Labs and Alchemy)
  • Internal sequencer infrastructure not reachable from public endpoints
  • Generic DDoS (amplification, reflection, flooding) that does not exploit protocol- or implementation-specific weaknesses
  • Theoretical transaction censorship by a small group of operators absent a demonstrated financial-impact path
  • Improperly configured nodes (node operator responsibility)
  • Hardware below recommended specs (node operator responsibility)
  • Local attacks against nodes requiring prior access to that node
  • Statesync peers are assumed trusted; findings against a malicious statesync peer are out of scope

Third-Party Code (report to the respective program)

  • Vulnerabilities in third-party protocols themselves (LayerZero core, etc.)
  • The Chainlink Data Streams aggregator and node operators, and incorrect data from third-party oracles in and of itself
  • Arbitrum-authored contract code for the canonical bridge / rollup (OCL / Arbitrum's program)
  • Core Blockscout software (Blockscout's program)
  • Alchemy's RPC, Data API, and account-abstraction (gasless transaction) infrastructure, including its bundler and paymaster.
  • Issuer-owned bridged token contracts (for example, USDG from the Global Dollar Network) and the third-party bridge paths that carry them.
  • Third-party applications, protocols, and infrastructure built on or integrated with Robinhood Chain, including the partners listed under the Ecosystem section of our About Robinhood Chain page.

Robinhood-Specific

  • Any repo, site, service, product, API, or resource not listed in the in-scope groups above
  • Robinhood's traditional brokerage / equities platform (this program covers Robinhood Chain and crypto products only)
  • Findings on Robinhood assets outside this program's scope belong in Robinhood's main bug bounty program; report them at robinhood.com/us/en/support/articles/report-security-vulnerabilities
  • Internal Robinhood infrastructure not reachable from public networks (corporate VPNs, internal monitoring, CI/CD)
  • Social engineering, physical attacks, attacks on Robinhood employees
  • Vulnerabilities requiring access to a user's device, account credentials, or 2FA
  • Findings reported to Robinhood through other channels prior to or concurrent with this program
  • Best-practice recommendations with no demonstrated exploit path

Default Out of Scope

Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.