Any user can see actual contract balance, which may leak sensitive info.
Likelihood:
High. This is a publicly exposed view function, meaning it can be called by any external address at any time. No special privileges or conditions are required to exploit this.
Impact:
Significant. The public disclosure of a contract's exact balance can reveal sensitive financial information. This could expose a user or a project's liquidity, making them a target for attackers, or provide a competitive disadvantage. It compromises the privacy of a core financial asset.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.