Security
Updated 2026-09-28
If you found a vulnerability in Unbacked, tell us at security@unbacked.xyz. We reward reports that help us protect creators' and brands' money, and we won't take action against good-faith research that follows the rules below.
In scope
Smart contracts: the escrow (UnbackedEscrow), its factory (UnbackedEscrowFactory) and the attestations registry (UnbackedAttestations) on Robinhood Chain.
The web app and APIs at unbacked.xyz: sign-in and sessions, payouts and payout roots, deposits and withdrawals, conversions and event hooks, the REST API, OAuth and the MCP server, the AI agents and anything that moves or reveals money or personal data.
Rewards
Critical (theft or permanent freezing of funds, forged payouts, taking over accounts at scale): up to $5,000.
High (unauthorized payouts or charges within limits, reading other users' private data, bypassing the payout hold): up to $1,000.
Medium and low: by assessment. We pay in USDG. The first clear report of an issue gets the reward.
Out of scope
Denial of service and load tests, spam, social engineering and phishing of our team or users, physical attacks, issues in third-party services (Privy, Robinhood Chain, bridges, social networks) unless our integration makes them exploitable, missing headers or best practices without a demonstrated impact, and self-XSS.
Rules
Test only against your own accounts and the testnet where possible. Don't access, change or keep other people's data beyond what proves the issue, and don't move funds that aren't yours. Don't disrupt the service. Give us 90 days to fix an issue before you disclose it, and tell us before you do.
Send the steps to reproduce it, the impact and, if you can, a proof of concept. We reply within 3 business days.