| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | codex | Pool shutdown ignores failed gauge withdrawals, risking permanent LP lock | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | EIP-1271 signature validation ignores signature bytes and relies solely on preapproved hashes | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| b912235e-edd4-44f6-a11e-2efc7ec4cf2e | complete | crit 0 high 0 | 5 | 3 months ago |