Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Invalid

Information in Blockchain is visible by anyone

Summary

Information in Blockchain is visible by anyone, even if the data structure is defined as private

Vulnerability Details

Soulmate::readMessageInSharedSpace is a function that allows soulmates to read a message in a shared slot in blockhain. However, many people might not be aware that everythin written in blockchain is public, and therefore can write something in the shared space thinking that only him and his soulmate can read the message calling Soulmate::readMessageInSharedSpace when in reality any user can!

Impact

Potential reveal of critical information of unaware users

Tools Used

Manual Review

Recommendations

State clearly that anything written in blockchain can be retrieved with proper tools and that nobody should write anything private in that slot!

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.