Robinhood
Maximum reward
$1,000,000
Severity
Max. Reward
Critical$1,000,000
High$100,000
Medium$25,000
Low$5,000
Deposit required
$30
Findings submitted
5
Start date
8 Sep 2026
KYC
Required to join
Please sign in as a researcher to join the bounty.
Log inIn scope
Severity
Min and Max Reward
CriticalUp to $1,000,000
High
Up to $100,000
Medium
Up to $25,000
Low
Up to $5,000
In Scope
- Tokenized stock contracts: the stock token, its factory, the access-control registry, the scaled-balance / multiplier logic, and the oracle-pause module. Includes unauthorized mint or burn, access-control flaws, blocklist or pause bypass, seizure (admin-burn and re-mint) abuse, and storage-layout / upgrade-safety bugs.
- Just-In-Time Funding contract: Robinhood's signature-authorized withdrawal contract for ETH and ERC-20. Includes signature-verification and authorization flaws, replay (nonce) and expiry bypass, access-control flaws across its admin, authorizer, withdrawer, and pauser roles, and abuse of the emergency-withdraw or pause logic.
- Canonical bridge and rollup configuration: the canonical Arbitrum contracts used by Robinhood Chain (rollup, delayed inbox, bridge, outbox, and CoreProxyAdmin) have public addresses on docs.robinhood.com/chain/protocol-contracts; bridging is documented at docs.robinhood.com/chain/bridging. The contract code is Arbitrum-authored and out of scope (Arbitrum's program). In scope: misconfiguration of the parameters and access controls Robinhood sets for these contracts, which are readable onchain from the public addresses.
Access-control flaws that let an unauthorized caller write the oracle multiplier or pause state are Tier 1 findings (see Tier 2 for the pricing logic itself).
Rewards are proposed maximums pending final Robinhood sign-off. Actual payouts are at Robinhood's discretion based on report quality, completeness, and exploitability.
Name | Description | Asset |
|---|---|---|
| StockFactory | stock token factory | |
| AccessControlsRegistry | access-control registry | |
| Stock Tokens & Tokenized ETFs | stock tokens, scaled-balance / multiplier logic, oracle-pause module | |
| Just-In-Time Funding | Signature-authorized withdrawal contract for ETH and ERC-20 | |
| Canonical Bridge & Rollup Configuration | Arbitrum rollup, delayed inbox, bridge, outbox, and CoreProxyAdmin - Robinhood-set parameters and access controls only (contract code is Arbitrum-authored and out of scope) |
Out of scope
The following issues are out of scope and not eligible for rewards.
For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.
L2 / Chain-Specific
- The Arbitrum node software (Nitro and ArbOS) and the sequencer, public RPC, and feed endpoints that run it. Robinhood Chain is an Arbitrum chain; protocol-level bugs in this software are covered by Arbitrum's bug bounty program.
- Validator software and operations (operated by Offchain Labs and Alchemy)
- Internal sequencer infrastructure not reachable from public endpoints
- Generic DDoS (amplification, reflection, flooding) that does not exploit protocol- or implementation-specific weaknesses
- Theoretical transaction censorship by a small group of operators absent a demonstrated financial-impact path
- Improperly configured nodes (node operator responsibility)
- Hardware below recommended specs (node operator responsibility)
- Local attacks against nodes requiring prior access to that node
- Statesync peers are assumed trusted; findings against a malicious statesync peer are out of scope
Third-Party Code (report to the respective program)
- Vulnerabilities in third-party protocols themselves (LayerZero core, etc.)
- The Chainlink Data Streams aggregator and node operators, and incorrect data from third-party oracles in and of itself
- Arbitrum-authored contract code for the canonical bridge / rollup (OCL / Arbitrum's program)
- Core Blockscout software (Blockscout's program)
- Alchemy's RPC, Data API, and account-abstraction (gasless transaction) infrastructure, including its bundler and paymaster.
- Issuer-owned bridged token contracts (for example, USDG from the Global Dollar Network) and the third-party bridge paths that carry them.
- Third-party applications, protocols, and infrastructure built on or integrated with Robinhood Chain, including the partners listed under the Ecosystem section of our About Robinhood Chain page.
Robinhood-Specific
- Any repo, site, service, product, API, or resource not listed in the in-scope groups above
- Robinhood's traditional brokerage / equities platform (this program covers Robinhood Chain and crypto products only)
- Findings on Robinhood assets outside this program's scope belong in Robinhood's main bug bounty program; report them at robinhood.com/us/en/support/articles/report-security-vulnerabilities
- Internal Robinhood infrastructure not reachable from public networks (corporate VPNs, internal monitoring, CI/CD)
- Social engineering, physical attacks, attacks on Robinhood employees
- Vulnerabilities requiring access to a user's device, account credentials, or 2FA
- Findings reported to Robinhood through other channels prior to or concurrent with this program
- Best-practice recommendations with no demonstrated exploit path
Default Out of Scope
Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.