| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Unprotected initialize allows hostile takeover of clones | no | — |
| medium | codex | `withdraw_admin_fees` can be reentered to withdraw fees multiple times | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | Unchecked ERC20 transfer result in `withdraw_admin_fees` can zero admin fees on failed transfer | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019bb005-2254-73e9-85d1-87e7597e1544 | complete | crit 0 high 0 | 6 | 3 months ago |