Skip to content

Wallet seeds stored unencrypted on disk #139

@kwsantiago

Description

@kwsantiago

Description

  • Seeds written to ~/.ddk/*/seed.ddk in plaintext
  • Located in ddk-node/src/seed.rs:11-23

Fix

  • Encrypt with user passphrase
  • Use AES-256-GCM or similar
  • Add key derivation (Argon2/PBKDF2)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions