T09 · Insecure Skill Coding Practices
- Location
trade.py:80- Finding
Wallet Private-Key Prefix Disclosed in Console Output
- Content
View full analysis
Vulnerability Details
File Location:
trade.py:80-84
Vulnerability Type: Sensitive credential exposure through logging
Risk Level: MediumVulnerable Code
python console.print(f"[cyan]Initializing ClobClient:[/cyan]") console.print(f" - Host: {host}") console.print(f" - Chain ID: {chain_id}") console.print(f" - Key (first 10 chars): {key[:10]}...") console.print(f" - Funder: {funder}")Technical Analysis
The authenticated client initialization path prints the first ten characters of the configured wallet private key. Because a Polygon private key normally starts with
0x, this discloses eight hexadecimal digits of secret key material.Private-key material must never be written to terminal output, logs, CI records, screenshots, or agent transcripts, even in truncated form. The disclosure occurs whenever
get_client()is invoked, including through balance retrieval, market queries, and order operations.This issue does not by itself disclose the complete private key, and brute-forcing the remaining key material would generally remain impractical. It nevertheless violates credential-handling requirements, permanently reveals part of a high-value signing secret, and can contribute to compromise when combined with another partial disclosure or weak key-generation process.
Attack Path
- The user configures
POLYMARKET_PRIVATE_KEY. - The user invokes a command that initializes
ClobClient, such aspolymarket balance,polymarket markets,polymarket buy, orpolymarket sell. get_client()reads the private key from the environment.- The code prints the first ten characters of the key to standard output.
- An attacker with access to terminal history, CI logs, captured agent output, support bundles, or screenshots obtains part of the wallet secret.
- The disclosed fragment may be correlated with other leaks or used to reduce the unknown key space if the key was ge ...[truncated 481 chars]
- The user configures
- Remediation
View remediation
Remediation Suggestions
- Remove the private-key logging statement completely; do not replace it with another partial representation.
- Log only a boolean status such as
Private key configured: yes. - Avoid including credentials in exception messages, debug logs, telemetry, or returned objects.
- Add automated secret-logging tests that capture console output and verify that no full or partial key value appears.
- Review and purge accessible logs that may already contain private-key prefixes.
- If other portions of the key may have been exposed elsewhere, rotate the wallet key and transfer assets to a newly generated wallet.
