stake.link

stake.link
DeFiHardhatBridge
27,500 USDC
View results
Submission Details
Severity: medium
Invalid

Initializer can be called by any address

Summary

The smart contract's initializer can be called by any address, potentially leading to unauthorized initialization and compromising the system's integrity. By front-running the contract to initialize the contract, the incorrect parameters may be supplied, leaving the contract needing to be redeployed.

Vulnerability Details

The vulnerability allows any address to call the smart contract's initializer, which can lead to unauthorized initialization and compromise the integrity of the system.

Impact

It can lead to unauthorized access, potential exploitation, and compromise the integrity of the system.

Tools Used

Manual Review

Recommendations

Implementing proper access control mechanisms will mitigate the risk of unauthorized initialization and safeguard the system's integrity.

Updates

Lead Judging Commences

0kage Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.