The bridge contract does not disable initializer on the implementation contract, which means that the initialize function can be called by anyone for the implementation contract which might lead to unexpected behavior because the caller becomes the owner of the implementation contract.
Likelyhood: Low/Medium Impact: Very low, the attacker can at most run the protocol on their side and lead a phishing campaign with an address deployed by Ark.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.