| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | codex | Refund logic never consumes PANDA or enforces refundMap, enabling unlimited ETH redemptions | no | — |
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| low | cast | Contract creation opcode present | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 50bc5866-a202-48b6-a7cd-e3e4d18a6a4c | complete | crit 0 high 0 | 6 | 3 months ago |
| 019b477e-cbc8-7096-9abb-2ae1f3a91571 | complete | crit 0 high 0 | 4 | 3 months ago |
| 019b3844-a483-70bc-af5a-ae67696e4562 | complete | crit 0 high 0 | 4 | 3 months ago |