
Robinhood Chain bug bounty on Cantina
Robinhood pays up to $1,000,000 on Cantina for bugs in Robinhood Chain contracts, wallet spending, and related web surfaces. Live as of September 8, 2026.
Robinhood Markets has opened a bug bounty on Cantina for Robinhood Chain. The program page is marked Live and lists a start date of 8 September 2026. The maximum reward is $1,000,000 for critical findings. High pays up to $100,000, medium up to $25,000, and low up to $5,000. A $30 deposit is required to submit.
The bounty covers smart contracts that power tokenization on Robinhood Chain, just in time spending for the Robinhood crypto wallet, public web interfaces and documentation, and the testnet faucet and explorer. Critical smart contract impact includes theft of tokenized assets, unauthorized mint or burn, permanent freezing of funds, and compromise of privileged roles.
Testing on mainnet or public testnet without prior authorization is prohibited. Use local tests, the testnet faucet, and the explorer. Do not disclose findings in public before Robinhood gives written permission. Reports should go through Cantina, with steps to reproduce, ideally within 24 hours of discovery.
KYC is required to join. People employed by Robinhood or its affiliates, and vendors who tested or helped build the affected code in the past six months, are not eligible. The Cantina page does not say the program is closed.