All findings

Hydrex ·Ethereum

MinterUpgradeableV4._initialize() one-time guard is a no-op

High

Verified with working PoC

initializergovernanceaccess control

Summary

_initialize() is meant to run exactly once, guarded by require(_initializer != address(0)). _initializer starts as the deployer's address and is set to address(1) after the first call - both states are nonzero, so the guard never actually blocks re-invocation.

Root cause

A one-time-latch guard that checks 'nonzero' instead of a specific sentinel value never actually latches - it resets identically on every call, so re-invocation is repeatable without limit.

Verification

Live precondition verified directly against unmodified mainnet state: storage slot 206 on the real Minter proxy already held address(1), proving _initialize() ran once as intended and remains re-callable by governor. PoC (real governor impersonated) confirmed a second call grants a brand-new permanent veHYDX lock with ~7.69M units of governance voting power for zero real collateral.

Verified against real, live deployed contract state.

Receipt on GitHub