Skip to content

"--memo" attribute is misleading #9122

Closed
@serge1peshcoff

Description

Summary

cosmos-sdk has the--memo attribute and its description doesn't describe it's public and anyone can see it. There are number of people who put their mnemonics there, exposing their wallets, probably because they though you should put a mnemonic here. See https://wasmywalletleaked.com/ and https://medium.com/frogvpn-ecosystem/how-we-found-exposed-wallets-in-cosmos-based-blockchains-a91f0ad5bb62

Problem Definition

See above.

Proposal

Two things can be done:

  1. updating the --memo description, explicitly stating memo is public
  2. renaming the --memo CLI option to something else (like --note)

For Admin Use

  • Not duplicate issue
  • Appropriate labels applied
  • Appropriate contributors tagged
  • Contributor assigned/self-assigned

Metadata

Assignees

Labels

T: Client UXT:DocsChanges and features related to documentation.

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions