complete
bytecode
findings
Bytecode-only review found one strong privileged-balance-drain issue and two medium-confidence accounting/call-handling issues. Selector names are inferred best-effort from runtime behavior; several conclusions rely on s...
Top findings
-
high
Owner-controlled source address can redirect public token payouts to arbitrary holder balances
-
medium
`allowance()` appears to report the approved amount, not the remaining spendable amount
-
medium
Token-for-ETH payout path ignores CALL failure after moving balances