Robinhood
Maximum reward
$1,000,000
Severity
Max. Reward
Critical$1,000,000
High$100,000
Medium$25,000
Low$5,000
Deposit required
$30
Findings submitted
6
Start date
8 Sep 2026
KYC
Required to join
Please sign in as a researcher to join the bounty.
Log inIn scope
Severity
Min and Max Reward
CriticalUp to $50,000
High
Up to $25,000
Medium
Up to $5,000
Low
Up to $1,000
Public-facing web interfaces, documentation portals, the testnet faucet, and the mainnet block explorer.
Special Focus Areas
- SSRF / RCE on the faucet backend
- Subdomain takeover on
*.chain.robinhood.com - Stored or reflected XSS via Robinhood Chain data on the explorer or public pages
Block Explorer
robinhoodchain.blockscout.com is in scope for Robinhood-specific issues only - for example stored or reflected XSS via Robinhood Chain data, or misconfiguration of the Robinhood instance. Vulnerabilities in core Blockscout software belong to Blockscout's own program.
Mainnet vs. Testnet
Mainnet (*.mainnet.chain.robinhood.com, chain ID 4663) is full severity. A testnet finding (chain ID 46630) that is reproducible on mainnet is full severity - demonstrate the mainnet vector rather than exploiting production. Testnet-only findings are discretionary.
Rewards are proposed maximums pending final Robinhood sign-off. Actual payouts are at Robinhood's discretion based on report quality, completeness, and exploitability.
Name | Description | Asset |
|---|---|---|
| Robinhood Chain Landing | Robinhood Chain product landing page | |
| Robinhood Chain Docs | Robinhood Chain documentation portal | |
| RHJ Docs | RHJ documentation portal | |
| Testnet Faucet | Robinhood Chain testnet faucet | |
| Testnet Explorer | Robinhood Chain testnet block explorer | |
| Mainnet Block Explorer | Robinhood-specific issues only - core Blockscout software goes to Blockscout's own program |
Out of scope
The following issues are out of scope and not eligible for rewards.
For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.
L2 / Chain-Specific
- The Arbitrum node software (Nitro and ArbOS) and the sequencer, public RPC, and feed endpoints that run it. Robinhood Chain is an Arbitrum chain; protocol-level bugs in this software are covered by Arbitrum's bug bounty program.
- Validator software and operations (operated by Offchain Labs and Alchemy)
- Internal sequencer infrastructure not reachable from public endpoints
- Generic DDoS (amplification, reflection, flooding) that does not exploit protocol- or implementation-specific weaknesses
- Theoretical transaction censorship by a small group of operators absent a demonstrated financial-impact path
- Improperly configured nodes (node operator responsibility)
- Hardware below recommended specs (node operator responsibility)
- Local attacks against nodes requiring prior access to that node
- Statesync peers are assumed trusted; findings against a malicious statesync peer are out of scope
Third-Party Code (report to the respective program)
- Vulnerabilities in third-party protocols themselves (LayerZero core, etc.)
- The Chainlink Data Streams aggregator and node operators, and incorrect data from third-party oracles in and of itself
- Arbitrum-authored contract code for the canonical bridge / rollup (OCL / Arbitrum's program)
- Core Blockscout software (Blockscout's program)
- Alchemy's RPC, Data API, and account-abstraction (gasless transaction) infrastructure, including its bundler and paymaster.
- Issuer-owned bridged token contracts (for example, USDG from the Global Dollar Network) and the third-party bridge paths that carry them.
- Third-party applications, protocols, and infrastructure built on or integrated with Robinhood Chain, including the partners listed under the Ecosystem section of our About Robinhood Chain page.
Robinhood-Specific
- Any repo, site, service, product, API, or resource not listed in the in-scope groups above
- Robinhood's traditional brokerage / equities platform (this program covers Robinhood Chain and crypto products only)
- Findings on Robinhood assets outside this program's scope belong in Robinhood's main bug bounty program; report them at robinhood.com/us/en/support/articles/report-security-vulnerabilities
- Internal Robinhood infrastructure not reachable from public networks (corporate VPNs, internal monitoring, CI/CD)
- Social engineering, physical attacks, attacks on Robinhood employees
- Vulnerabilities requiring access to a user's device, account credentials, or 2FA
- Findings reported to Robinhood through other channels prior to or concurrent with this program
- Best-practice recommendations with no demonstrated exploit path
Default Out of Scope
Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.