| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | yes | yes |
| high | detector | ETH value transfer possible | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| medium | codex | `allowance()` appears to expose total approved amount while `transferFrom()` enforces a separate cumulative-spend counter | no | — |
| low | codex | Fallback path appears payable and silently succeeds, which can trap ETH in the token contract | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019b3836-3555-70ef-8007-1b2c005df2ea | complete | crit 0 high 2 | 4 | 3 months ago |