NFTBridge
60,000 USDC
View results
Submission Details
Severity: low
Valid

Missing `_disableInitializer` in Bridge Implementation Constructor

Vulnerability Details

The bridge contract does not disable initializer on the implementation contract, which means that the initialize function can be called by anyone for the implementation contract which might lead to unexpected behavior because the caller becomes the owner of the implementation contract.

Updates

Lead Judging Commences

n0kto Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

finding-initialize-on-implementation

Likelyhood: Low/Medium Impact: Very low, the attacker can at most run the protocol on their side and lead a phishing campaign with an address deployed by Ark.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.