Hydrex ·Ethereum
MinterUpgradeableV4._initialize() one-time guard is a no-op
Verified with working PoC
Summary
_initialize() is meant to run exactly once, guarded by require(_initializer != address(0)). _initializer starts as the deployer's address and is set to address(1) after the first call - both states are nonzero, so the guard never actually blocks re-invocation.
Root cause
A one-time-latch guard that checks 'nonzero' instead of a specific sentinel value never actually latches - it resets identically on every call, so re-invocation is repeatable without limit.
Verification
Live precondition verified directly against unmodified mainnet state: storage slot 206 on the real Minter proxy already held address(1), proving _initialize() ran once as intended and remains re-callable by governor. PoC (real governor impersonated) confirmed a second call grants a brand-new permanent veHYDX lock with ~7.69M units of governance voting power for zero real collateral.
Verified against real, live deployed contract state.
Receipt on GitHub