set_secret function
stores secret directly on-chain which is publicly visible to anyone on the public mempool.
Likelihood: high
Any user setting the secret for vault is publicly visible to anyone on the public mempool
Impact: high
Vault containing funds can be drained out by the attacker using public mempool to exploit the vault
Use secure way of storing the secrets to prevent the exploit for draining the funds
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.