State variables (private
) in a contract only limit their invocation scope and remain accessible on the chain. Referable study material: Ethernaut Level 12 - Privacy
The sensitive data of s_password
will be accessed in the chain and will lead to sensitive data leakage!
Manual Review
Do not store any sensitive data in the contract, as any data in the contract can be accessed.
Private functions and state variables are only visible for the contract they are defined in and not in derived contracts. In this case private doesn't mean secret/confidential
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.