[gage]
Loading wallet…

Security research · Robinhood Chain

Help protect user funds.

The gage bug bounty rewards researchers who find and responsibly report vulnerabilities in our smart contracts.

$5,000

Announced for qualifying Critical contract bugs that can cause loss of user funds in our vaults. Valid High, Medium and Low bugs are also rewarded, with amounts assessed individually.

Report privately

Send it through the report form. It follows the Immunefi template and asks for a refundable deposit of 15 USDC on Base, paid from your wallet in one signature with no gas. The deposit comes back with every valid report, even a Low; it stays with gage for duplicates, non-reproducible claims and spam. The team reads reports in private and answers on your report page and by email.

Agents send the same fields as JSON with an x402 payment to POST https://support-production-707f.up.railway.app/reports; the agent docs show the body and a client. Never share exploit code, credentials or vulnerability details in public replies, GitHub issues or group chats.

Contract scope

Gage-deployed smart contracts on Robinhood Chain mainnet, chain ID 4663. Focus on escrowed collateral, lender funds and withdrawable balances, including gage integrations that can affect those funds.

Contract addresses are from the mainnet deployment manifest dated 8 September 2026. Verify bytecode, configuration and connected contracts at your fork block. Report the affected deployment and exact funds at risk.

Third-party systems are not independent targets. Web/API findings may be reported privately; the contract announcement does not establish a separate web/API reward schedule.

Severity follows impact

We use the Smart Contracts category of Immunefi's Severity Classification System v2.3. These are relevant examples; the linked standard supplies the full classification.

Critical
Theft of user principal or collateral, permanently inaccessible funds, or protocol insolvency.
High
Theft or permanent freezing of unclaimed rewards, or temporary freezing of user funds.
Medium
Demonstrated griefing, gas theft or unbounded gas consumption.
Low
Failure to deliver promised returns without loss of value.

Severity depends on demonstrated impact and prerequisites. Extraction claims should include net profit; freezing and griefing do not require attacker profit. Expected admin powers, normal market movements and speculative scanner alerts alone are not validated bugs.

This is a gage-run bounty. Using Immunefi's standard does not imply Immunefi hosting, administration or a payment guarantee. The announcement leaves payout currency, timing and whether $5,000 is per bug or a shared pool unspecified; confirm those details privately.

Rules of engagement

  1. Test locally. Use isolated environments or local forks. Ordinary read-only chain queries are fine. Do not broadcast exploit transactions or manipulate live pools, prices or oracles.
  2. Protect users. Do not move or freeze real funds, access other people's accounts, extract private data or use discovered credentials. Stop and report sensitive material privately.
  3. Keep services available. No denial of service, high-volume scanning, spam, brute force, phishing, social engineering or testing of third-party systems.
  4. Provide a reproducible proof. Include chain, addresses, fork block, root cause, executable local steps, prerequisites and evidence of impact. For extraction, show before/after balances, capital and costs; for freezing, show duration and recovery limits.
  5. Coordinate disclosure. Report promptly and privately; coordinate remediation and publication before sharing technical details. Duplicate reports of one underlying issue do not establish separate bugs.
  6. Agents follow the same rules. AI-assisted research is welcome. The submitter must verify the evidence and keep their tools within scope. Agents must not autonomously sign or broadcast exploit transactions.

Read the full policy and submission checklist before testing. A report is assessed for reproducibility, reachability and impact before a reward decision.