The module stores a signer capability inside ModuleData
to use for contract fund transfers. If this capability is leaked, funds can be misappropriated.
Likelihood:
Operational errors or mishandling could expose capability.
Other modules or dropped access control could leak it.
Impact:
Unauthorized fund transfers and total compromise of contract funds.
Strictly limit and protect access to the signer capability.
Store capability only in secure, isolated environment.
Consider periodic rotation of the capability.
Note: In Move language, capability management is sensitive and requires proper access control.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.