| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | slither | ExchangeProxy.transferAll(TokenInterface,uint256) (contracts/Contract.sol#775-788) sends eth to arbitrary user | no | — |
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Unlimited approvals to user-supplied pools allow token drain | no | — |
| low | codex | Public swap functions can sweep any ERC20 balance held by the proxy | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019be3d6-8201-73d9-b7fe-2f43c4915ca9 | complete | crit 0 high 0 | 7 | 2 months ago |
| 019b477e-b966-7279-8c94-ec9d584ebeb8 | complete | crit 0 high 0 | 2 | 3 months ago |
| 019b3844-9671-7259-b7d4-0cb1859a2d90 | complete | crit 0 high 0 | 2 | 3 months ago |