All findings

Orvex ·Robinhood Chain

MinterUpgradeableV3._initialize() one-time latch never actually latches

Medium

Verified with working PoC

Contract: 0xb0B3B13B9122711eA9853C633CC93A925A53754f

initializergovernanceemission schedule

Summary

The guard require(_initializer != address(0), 'already initialized') is satisfied by any nonzero value, including the sentinel it sets on completion - so it never blocks a second call. The governor can re-run the genesis-distribution function at will, silently rewinding whatever decay curve the emission schedule applies.

Root cause

A one-time-latch that checks 'nonzero' instead of a specific sentinel value doesn't actually latch - it resets identically every call. Proven independent of the separate missing-burnFrom token bug: the max=0 path resets active_period/getCurrentWeek back to 0 with zero dependency on that other gap.

Verification

Fork PoC: called the real genesis function as governor, simulated 10 real epochs passing via permissionless update_period() calls (getCurrentWeek reached 10), then called it again and confirmed the week counter was silently rewound to 0 - a second run that should have reverted at the guard instead executed in full.

Verified against real, live deployed contract state.

Receipt on GitHub