Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The script prints the fully signed withdrawal URL, including the EIP-712 signature and all withdrawal parameters, directly to stdout. In many real environments stdout is captured by shell history, CI/CD logs, process supervisors, terminal recording tools, or shared support logs; anyone who obtains the URL may be able to trigger the withdrawal before expiry, effectively turning log exposure into credential exposure.
