The owner should be able to update the secret.
Using move_to will abort if a Vault already exists, there’s no move_from/replace logic, so the secret becomes immutable after first set.
Likelihood:
Triggers on the second attempt to set the secret.
Owner cannot rotate/update secrets, poor UX and potential security risk.
Consider Making this changes
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.