| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | slither | DragonCurve.refundFrom(address,uint256) (src/DragonCurve.sol#162-172) sends eth to arbitrary user | no | — |
| high | detector | Authorization based on tx.origin | no | — |
| high | slither | DragonCurve.refund(uint256) (src/DragonCurve.sol#156-161) sends eth to arbitrary user | no | — |
| medium | detector | ETH value transfer possible | no | no |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | slither | OperatorFilterer._registerForOperatorFiltering(address,bool).functionSelector__registerForOperatorFiltering_asm_0 (lib/closedsea/src/OperatorFilterer.sol#30-31) is written in both | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| low | cast | Contract creation opcode present | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019bab3b-ab92-73e3-a078-3ec5304af404 | complete | crit 0 high 0 | 8 | 3 months ago |
| 019b477e-d204-702b-9964-b069deb97524 | complete | crit 0 high 0 | 4 | 3 months ago |
| 019b3844-a917-72ed-a1ae-6b8b4b686d24 | complete | crit 0 high 0 | 4 | 3 months ago |