| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Upgradeable proxy can be taken over if not initialized atomically | no | — |
| high | detector | Untrusted DELEGATECALL target reachable | no | no |
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | cast | DELEGATECALL present | no | — |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | Dispute deposit accounting assumes full transfer, risking permanent dispute lock with fee-on-transfer tokens | no | — |
| low | codex | `tx.origin` allows bypassing operator-only claim policy | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 544294f2-85eb-4ecd-9643-38f7e97bcdaf | failed | crit 0 high 0 | 7 | 3 months ago |
| 0f2dae3b-fa8e-4cc8-9793-fb705919c460 | failed | crit 0 high 0 | 10 | 3 months ago |