The vault is intended to store a secret that only the owner can access. However, the secret is not hashed before stored in plain UTF-8 string anyone who queries the blockchain state.
Likelihood: High
Anyone with access to the blockchain state can read the vault's secret field.
Impact: High
Sensitive information intended to be private are exposed publicly on chain.
Use the blockchain explorer or indexed to ge back the data
Hash the secret off-chain before storing it on-chain
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.