Orvex ·Robinhood Chain
MinterUpgradeableV3._initialize() one-time latch never actually latches
Verified with working PoC
Contract: 0xb0B3B13B9122711eA9853C633CC93A925A53754f
Summary
The guard require(_initializer != address(0), 'already initialized') is satisfied by any nonzero value, including the sentinel it sets on completion - so it never blocks a second call. The governor can re-run the genesis-distribution function at will, silently rewinding whatever decay curve the emission schedule applies.
Root cause
A one-time-latch that checks 'nonzero' instead of a specific sentinel value doesn't actually latch - it resets identically every call. Proven independent of the separate missing-burnFrom token bug: the max=0 path resets active_period/getCurrentWeek back to 0 with zero dependency on that other gap.
Verification
Fork PoC: called the real genesis function as governor, simulated 10 real epochs passing via permissionless update_period() calls (getCurrentWeek reached 10), then called it again and confirmed the week counter was silently rewound to 0 - a second run that should have reverted at the guard instead executed in full.
Verified against real, live deployed contract state.
Receipt on GitHub