| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | ETH value transfer possible | no | no |
| medium | codex | Minting uses requested deposit amount rather than actual received amount | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| low | codex | Transfer destination check always passes due to `||` | no | — |
| low | cast | Contract creation opcode present | no | — |
| info | codex | Timelock bypass via changeVault | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| a4ff4f05-4e3e-4551-98c5-e84e98ac3bc8 | complete | crit 0 high 0 | 8 | 3 months ago |