Intent-Code Divergence
Medium
- Confidence
- 99% confidence
- Finding
- The wallet encryption key is deterministically derived from USER and HOME environment variables, which are low-entropy and often guessable or observable by local users and processes. This means anyone who obtains the wallet file can likely reconstruct the decryption key and recover the private key, defeating the purpose of encrypting wallet material at rest.
