
Work Here?
Cantina offers an agentic security platform called Clarion that merges SIEM, EDR, SOAR, and CSPM into one system. It runs autonomous, domain-expert AI agents to detect vulnerabilities, prioritize threats, coordinate remediation, and verify fixes, while building a security memory layer that creates a living digital twin of an organization’s assets and relationships for context-aware risk assessment. What sets Cantina apart is its agent-based automation, support for out-of-the-box, customizable, and community-developed agents, and its focus on regulated industries, with strategic access to OpenAI and involvement in Anthropic’s Cyber Verification Program. The goal is to reduce security noise and automate the entire security lifecycle so teams can focus on impactful issues and faster, safer risk management.
Industries
Enterprise Software
Cybersecurity
Company Size
201-500
Company Stage
Early VC
Total Funding
$8M
Headquarters
Miami, Florida
Founded
2023
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$8M
Above
Industry Average
Funded Over
1 Rounds
Health Insurance
Dental Insurance
Vision Insurance
401(k) Company Match
The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities.
Polymarket launches bug bounty program on Cantina with rewards of up to $5M. Published: April 14, 2026 at 3:16 am Updated: April 14, 2026 at 3:17 am Edited and fact-checked: April 14, 2026 at 3:16 am Polymarket launches a Cantina-hosted bug bounty offering up to $5M, targeting vulnerabilities across smart contracts, web systems, oracles, and collateral infrastructure on its Polygon-based platform. Prediction market platform Polymarket introduced a bug bounty program in partnership with the Web3 security platform Cantina, offering rewards of up to $5 million. The initiative targets vulnerabilities across the platform's full infrastructure, including smart contracts, collateral systems, oracle integrations, and its web application. The platform, known for enabling users to place real-money bets on events such as elections, central bank decisions, and major sports outcomes, has processed billions of dollars in trading volume, particularly during the 2024 United States election cycle. Its contracts operate on the Polygon Proof-of-Stake network and incorporate multiple settlement pathways, several signature verification methods, and a system that bridges stablecoins with an internal token. The program is divided into two main areas. The first focuses on exchange and settlement infrastructure, which includes a set of 18 smart contracts responsible for trade execution, fee handling, collateral management, oracle-based resolution, and wallet deployment. It also covers integrations with the Gnosis Conditional Tokens framework, though core issues within that framework are excluded. The second area addresses vulnerabilities within the web platform, including critical risks such as remote code execution, data breaches, subdomain takeovers involving wallet interaction, and malicious transaction injection. Incentive structure and severity classification. Rewards are structured by severity. For smart contract vulnerabilities, critical findings can receive between $50,000 and $5 million, while high-severity issues may earn up to $500,000. Web-related vulnerabilities offer lower maximum payouts, with critical issues reaching up to $250,000. Severity levels are determined based on a standardized framework that considers both impact and likelihood. Several technical features are expected to attract security researchers. The platform's newer exchange contracts use low-level assembly optimizations for processes such as hashing and event handling, which can introduce risks not typically present in higher-level code. The signature verification system supports multiple validation types, each interacting with a nonce mechanism designed to prevent replay attacks, creating potential edge cases. The collateral system adds further complexity by converting user-deposited stablecoins into an internal token through an upgradeable contract, which then interacts with a conditional token framework to manage positions. Additional adapter layers are used for multi-outcome markets, increasing the number of potential vulnerability points. Oracle functionality is handled through UMA's Optimistic Oracle, with adapter contracts linking oracle results to market settlement also included in scope. In order to qualify for higher-tier rewards, submissions must include detailed proof-of-concept demonstrations. Smart contract reports require reproducible tests on a local Polygon environment, while web vulnerabilities must include clear replication steps and supporting evidence. All reports are submitted via Cantina, with prompt disclosure encouraged. The program highlights Polymarket's complex architecture and significant financial activity, positioning it as a high-value target for security research. Disclaimer. In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, Mpost Media Group suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice. Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance. Alisa Davidson Hot Stories by Alisa Davidson April 14, 2026 by Alisa Davidson April 14, 2026 by Alisa Davidson April 13, 2026 by Alisa Davidson April 13, 2026 by Alisa Davidson April 14, 2026 by Alisa Davidson April 14, 2026 by Alisa Davidson April 13, 2026 by Alisa Davidson April 13, 2026
Paxos strengthens security stack with cantina-powered bounty program. * C. Monasterio * Published: March 27, 2026 * 7:11 pm * Updated: March 27, 2026 * 7:11 pm Home > companies > Paxos strengthens security stack with cantina-powered bounty program. Table of Contents * Paxos offers up to $1,000,000 in the USDG stablecoin for researchers who detect critical vulnerabilities in its Web2 and Web3 infrastructure. * The program is launched in collaboration with Cantina, a leading audit platform, fulfilling previous commitments to the Aave and LlamaRisk communities. * The initiative will cover core assets such as PYUSD, PAXG, and USDG, including smart contracts and cross-chain movements. Paxos and Cantina join forces to bring a public Bug Bounty program to the market. This initiative seeks to attract researchers capable of identifying security flaws within the Paxos ecosystem, aiming to guarantee the integrity of its digital financial services. This program was created due to the increasing complexity of threats in the crypto sector, where the capitalization of assets like Pax Gold (PAXG) and PayPal USD (PYUSD) requires a robust defense. With a seven-figure reward, economic incentives are aligned with the Total Value Locked (TVL) in their contracts, strengthening trust in their interoperability bridges and public APIs. Since its inception, the company has maintained rigorous standards through third-party audits and constant penetration testing. However, the formalization of this bounty program adds an extra layer of external vigilance to detect "edge cases" or extreme use cases. Through the alliance with Cantina, access to native Web3 communication with specialized technical expertise will be possible. This synergy is fundamental for holistically evaluating both traditional services and the firm's decentralized innovations. Expansion of surveillance in digital assets and smart contracts. During the first few months, the program will operate under an "invitation" basis, specifically for researchers active within the Cantina network. However, its scope is broad, covering everything from web domains and API services to the underlying infrastructure that allows the movement of assets between different blockchain networks. The bounty payment will be made in the USDG stablecoin, underscoring the brand's commitment to its own ecosystem of regulated assets. Not only will those who discover bugs be rewarded, but this strategy also promotes the adoption and liquidity of its new market launches. With this launch, Paxos consolidates itself as a leader in compliance and security, inviting the global community to audit its systems to build a more resilient and transparent financial environment for all its users.
Cantina and OKX Labs launch $1M Onchain Bug Bounty to strengthen production DEX security. Cantina and OKX Labs have launched a $1 million onchain bug bounty program to continuously secure and strengthen production smart contracts powering OKX's decentralized exchange infrastructure. Web3 security provider Cantina has partnered with OKX Labs to launch the $1 million OKX DEX Onchain Bug Bounty Program, a targeted effort to harden live smart contracts that power OKX's decentralized exchange infrastructure on mainnet. The initiative concentrates solely on production deployments, establishing a continuous, structured security review process intended to bring rigorous, repeatable standards to the upkeep of real-world onchain systems. By framing the program around production-grade contracts rather than testnet code or prototypes, the partnership aims to align security incentives with the operational realities that matter most to users and liquidity providers. The program invites independent security researchers to responsibly disclose vulnerabilities affecting OKX Labs' DEX routing stack and associated onchain components, including multi-ecosystem router implementations that operate across several chains. Scope definitions, authoritative repositories, and deployment references have been published on the official bounty page to provide clarity and reduce ambiguity for submitters, while ensuring that reported issues map directly to production risk. Cantina will manage submissions and triage, applying a disciplined workflow intended to preserve high-signal reporting and fast remediation. Establishing structured, production-focused security framework for onchain DEX systems. Designed as an operating practice rather than a one-off event, the bounty sets out clear eligibility criteria, responsible disclosure expectations, and rules of engagement that reflect the unique demands of critical financial infrastructure. Rewards are structured by severity and real-world impact, with explicit ranges tied to production exposure; the program documentation details how findings are assessed and prioritized so that fixes can be coordinated with minimal disruption to live services. This transparent approach aims to create aligned incentives for researchers and the OKX Labs security team while reducing the window of exposure for discovered vulnerabilities. Beyond immediate vulnerability discovery and patching, the program is positioned to improve long-term operational resilience by normalizing continuous third-party review, accelerating time-to-fix, and feeding security intelligence back into development and deployment practices. By combining Cantina's managed bounty operations with OKX Labs' production onchain footprint, the initiative seeks to raise the bar for how complex DEX systems are defended in the open, incentivizing proactive research and measurable improvements to user fund protections across the onchain trading stack. Disclaimer. In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, Mpost Media Group suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice. Alisa, a dedicated journalist at the MPost, specializes in cryptocurrency, zero-knowledge proofs, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
Automata's monthly update: issue 81. * Release of the SGX attestation quote API for verification * Rework of UI with components from shadcdn * Support for DCAP v1.1 and new testnets and mainnets (including HyperEVM) on the indexer * Set up of infrastructure on bare-metal servers * Fullnode upgrade and deployment * ERC-8004 standardizes how agents earn trust, so they can prove correct execution and that the intended code and model ran on genuine secure hardware with TEE attestations. Automata's suite of production-ready TEE verifier stacks for Intel SGX/TDX, AMD SEV-SNP, and AWS Nitro makes the continuous verification of hardware-attested agents practical onchain. * Automata releases DCAP Attestation v1.1, which adds Pico zkVM + Quote V5 support, configurable TCB Recovery trust controls, and major cost/UX upgrades (EIP-7951 readiness and an improved Attestation Explorer) to verify agent integrity at scale * Automata resolves prover privacy for zkVMs like Brevis's Pico Prism by running proof generation inside verifiable TEEs, so private witness inputs stay encrypted from the operator and only the proof leaves the enclave. * Its DCAP Attestation library was featured in whitepapers of t1 Protocol and Jovay Network (by Ant Digital). * Automata announces its collaboration with Cantina to strengthen the hardware-verifiable agent stack with security tooling and bug bounty support. * Check out its new, refreshed landing page for 1RPC.io, the TEE-attested relay for agents and Web3 * 1RPC.ai adds support for the latest models, including GPT5.1, Claude Opus 4.5, and Gemini 3.0 Pro Preview * Its Research Lead, Yaoxin, was in Buenos Aires for Devconnect and shared more about how Automata is building canonical layer for hardware-attested agents. Check out a snippet of his talk at SpaceComputer's Frontier Forum here. About Automata Network. Automata Network is a machine attestation layer that integrates TEEs into AI systems and decentralized networks. This includes verifiable AI infrastructure with 1RPC, Multi-Provers for Stage 2 rollups like Scroll and Linea, and TEE-capable GPUs with World (formerly Worldcoin) Foundation. Get Automata Network's stories in your inbox. Join Medium for free to get updates from this writer.
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
201-500
Company Stage
Early VC
Total Funding
$8M
Headquarters
Miami, Florida
Founded
2023
Find jobs on Simplify and start your career today