Intent-Code Divergence
High
- Confidence
- 99% confidence
- Finding
- The script states that wallet proofs are encrypted, but it creates a plain tar.gz archive and uploads it directly to IPFS. IPFS CIDs are content-addressed references, not encryption, so anyone who obtains the CID or accesses the local node/pinning path may retrieve sensitive wallet data and metadata.
