complete
source
findings
Found 3 issues: multiple constructor-deployed contracts can be hijacked through permissionless initializers, mailbox-authenticated hooks can be triggered directly by anyone for the current latest message, and recipient-s...
Top findings
-
high
Permissionless initializers let the first caller seize control and mint supply
-
high
Anyone can call post-dispatch hooks directly for the current latest message
-
low
DestinationRecipientRoutingHook quotes the wrong hook for recipient-specific routes