All reports
mediumAccess controlEVM-Solidity

Rigor Protocol: Incorrect initialization of smart contracts with Access Control issue

Payout
$0
Protocol
Rigor Protocol
Disclosed
Aug 7, 2026
Source
code4rena

Rigor Protocol's upgradeable contracts ship with initialize() functions that lack any caller authorization, and its proxy deployments pass an empty data field so initialization is deferred until after deployment. In the intervening window, a mempool-watching a …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.