Problem
The initialize function may not prevent re-initialization, allowing the vesting schedule to be overwritten.
Impact
- Vesting schedule could be changed after initialization
- Beneficiary could be changed
- Total amount could be modified
Fix
Add re-initialization guard:
if env.storage().instance().has(&DataKey::Beneficiary) {
return Err(VestingError::AlreadyInitialized);
}
Location
contracts/vesting-wallet/src/lib.rs, initialize function.
Problem
The initialize function may not prevent re-initialization, allowing the vesting schedule to be overwritten.
Impact
Fix
Add re-initialization guard:
Location
contracts/vesting-wallet/src/lib.rs, initialize function.