Without proper access control, any user can call the set_secret function and replace the existing secret. This completely defeats the purpose of a private vault and can cause loss of stored data for the owner. On Aptos, there’s no way to recover overwritten data, making the vulnerability!!!
Likelihood: High
The vulnerability is trivial to exploit and does not require any special conditions beyond calling the function.
IMPACT : High
Recommended Mitigation
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.